Manage Users

The following user roles can manage users in IBM® Storage Protect for Cloud: tenant owner, service administrators, and customized administrators assigned with the Management permission. For more details about the user roles, refer to IBM Storage Protect for Cloud User Roles.

To manage IBM Storage Protect for Cloud users, navigate to Management > User management. On the User management page, refer to the following instructions to manage users/groups:
  • Add – Click Add and refer to the instructions in the Add Users section.
  • Edit – Select one user and click Edit. Then, refer to the instructions in Edit User Permissions.
  • Delete – Select one or multiple users, and then click Delete. In the confirmation window, click Confirm. All selected users and related data will be deleted.
  • Set as tenant owner – Select a service administrator in the Activated status, and then click Set as tenant owner. In the confirmation window, click Confirm. The email notification will be sent to the new tenant owner and the original tenant owner.
  • Reset MFA – This is available for organizations which has enabled the MFA policy for local accounts setting in Administration > Security. If a user needs to reconfigure their MFA settings, such as when switching to a new device, select the user's local account, ensure it is in the Activated status, and then click Reset MFA.
  • Deactivate – Select one or multiple users in the Activated status, and then click Deactivate. Deactivated users are not removed from IBM Storage Protect for Cloud but are restricted from accessing IBM Storage Protect for Cloud.
  • Activate – Select one or multiple users in the Deactivated / Not Activated status, and then click Deactivate.
  • Unlock – If a user enters an incorrect password consecutively more than three times, the user account will be locked for an hour. Instead of waiting for the system to automatically unlock the account after an hour, tenant owner and service administrator can manually unlock the account. To unlock an account, select the account and click Unlock.
  • Filter – Set a filter to view users and groups by referring to the instructions below:
    1. Click Filter on the upper-right corner of the page. The Filter pane appears on the right of the page.
    2. In the Filter pane, configure conditions for the Role, Service, Sign-in method, or Geo location criteria.
      Note: The Geo location criterion is only available when your tenant has Multi-Geo Capabilities in IBM Storage Protect for Cloud Microsoft 365 service.
    3. Click Apply.
Note the following:
  • Logged-in tenant owner and service administrators cannot edit, deactivate, or delete their own accounts.
  • Application administrators can only add/edit tenant users and manage available services for which they are application administrators.
  • Logged-in application administrators cannot edit their own accounts.
  • To manage the security settings for users in your IBM Storage Protect for Cloud tenant, refer to Configure Advanced Settings