Settings → User Access → Users
Manage the user accounts that have access to this MisterShell workspace. Users can authenticate locally (with a password stored by MisterShell) or through an external identity provider (LDAP, OIDC, SAML). This tab is where administrators create, edit, and deactivate users, and where roles are assigned.
What you can do
- Create new local users.
- Edit a user’s name, roles, and active status.
- Reset a local user’s password.
- Reset a user’s authenticator enrollment.
- Delete a user.
Table columns
| Column | Notes |
|---|---|
| The user’s login identifier. | |
| Name | First and last name. |
| Auth Type | Badge — blue LOCAL for password-based accounts, green LDAP, OIDC, or SAML for federated accounts. |
| Active | Green check for active, red cross for deactivated. |
| Roles | Chips listing every role assigned to the user. |
| Actions | Edit / Reset password (local only) / Reset MFA enrollment / Delete. |
Common tasks
Create a user
This form always creates a local (password-based) account. Federated identities are established during external sign-in. With external_auth_auto_provision enabled (the default), MisterShell creates a new account or re-links an existing account with the same email address. With it disabled, only an identity already linked to that exact provider can sign in; creating a local user here does not pre-authorize external sign-in.
- Click Create User at the top right.
- Fill the form:
- Email — used as the login.
- First Name / Last Name — for display.
- Password / Confirm Password — type one, or click Generate to produce a secure password you can copy.
- Roles — tick the roles to assign. Users without a role have no access.
- Active — leave on to allow login, switch off to pre-create a disabled user.
- Click Create. The new user appears in the table.
Edit a user
- Click the blue edit icon.
- Update name, roles, or active status. Email cannot be changed.
- Click Update.
Reset a user’s password
Only available for LOCAL users. Federated users must reset through their identity provider.
- Click the key icon on the user’s row.
- Click Reset in the confirmation dialog. MisterShell generates a new random password — you do not choose one.
- The new password is displayed once, in its own dialog with a copy button. Share it securely with the user; it will not be shown again.
Resetting a password invalidates all of the user’s existing sessions immediately — they are signed out everywhere and must sign in with the new password.
Reset MFA enrollment
Use this action when a Local or LDAP user loses access to both their authenticator and recovery codes.
- Click the Reset MFA enrollment icon on the user’s row.
- Review the account in the confirmation dialog.
- Click Reset.
The reset invalidates current MFA proof and clears the authenticator enrollment. It does not disable the provider policy, so a user whose provider requires an authenticator must enroll again at the next sign-in. The built-in Local recovery account cannot be enrolled or reset. Password resets do not clear MFA enrollment.
Deactivate a user
Editing a user and unchecking Active immediately prevents new sign-ins but preserves history (audit logs, session recordings, ownership of reports). Reactivate the same way.
Delete a user
- Click the red trash icon.
- Confirm in the dialog.
Deletion is permanent. It also removes the user’s personal vault entries and all their historical values. Team vault entries remain available to their selected roles, and security audit evidence follows its normal retention policy. For reversible removal prefer Deactivate.
Federated users
With external_auth_auto_provision enabled (the default), a first sign-in through an external provider creates a user or re-links the existing account with the same email address. With it disabled, new identities are refused. Role assignment follows the mapping rules under Auth Providers. You can edit a federated user’s name, roles, and active status here, but not their email. Two more defaults are worth knowing:
- Names are re-synced from the provider on every sign-in (setting
external_auth_sync_attributes, on by default), so a local name edit lasts only until the user next signs in. - Group mappings are authoritative for roles by default (setting
external_auth_override_roles): role changes you make here are replaced by the provider’s group mappings at the user’s next sign-in. Adjust the mappings on the provider instead, or switch the setting to additive mode.
Permissions
- Read:
app.users.read. - Create / edit / reset password / reset MFA enrollment:
app.users.write. - Delete:
app.users.delete.