User Management - Part 6 - Tools

Modified on Tue, 22 Sep at 4:44 PM

User Management Tools


Introduction


There are three tabs in the Users area (Administration > Users) which help managers monitor users’ activity in the system, check if their email address is working correctly and interrogate their personal preferences:


  • The Users’ activities tab collects login information.

    Tip
    Additionally, each user record displays a graph at the bottom of the General tab which shows the user’s number of logins per month.


  • The Suppressed Emails tab lists any users whose email address has been blocked by the system.

  • In the Reports tab, a list of each user’s personal preferences can be generated.


The user list itself is a fourth place to monitor activity. Each row shows whether the user is currently Signed in, Signed out or Locked Out, together with the time of their last login and the duration of their current session. A Logout button is available to end the session of a signed-in user, which requires the permission “User Accounts:Log Users Out”, and an Unlock Account button releases a user who has been locked out.


Users’ activities tab


The Users’ activities tab within iPassport records all users’ login history. Information displayed includes login duration and concurrent user logins.


The tab is available to any user whose role carries the permission “User Accounts:Preference Report”. That permission is the only requirement: the Administration Editor role is not needed, and holding the Administration Editor role without that permission will not make the tab visible.


Search Activity


To search for the activity of a specific user, simply enter their name into the ‘User Name’ search field.



The search can be limited to a specified date range, using the ‘Activity Start Date’ and the ‘Activity End Date’ fields. Click in the fields to bring up a pop-up calendar where dates can be selected. Note that the tab does not open on the full login history: the ‘Activity Start Date’ arrives pre-filled with the date one month before today, so sessions older than a month are only returned once that date is cleared or changed.


On enterprise accounts there is also a ‘Facility’ drop-down, which restricts the results to users whose default organisational unit belongs to the selected facility. This field is not present on non-enterprise accounts.


The results show when the user logged in and logged out and the total session time. Each row represents a different login/logout period, and also reports the ‘Licence Type’ held during that session (Editor, Read Only, Reserved or Admin) and the ‘Licence Source’, which is either Account or Facility followed by the name of the facility. Enterprise accounts show an additional ‘Facility’ column for the user themselves.


Licence use during the session is reported in separate columns rather than as a single combined figure. ‘Account Editor Licences’ and ‘Account View-only Licences’ each show the number of licences in use out of the total available, and on enterprise accounts ‘Facility Editor Licences’ and ‘Facility View-only Licences’ are shown as well. Wherever one of these counts is greater than zero, a ‘View users’ link appears beneath it; click the link to load the names of the users who were holding that type of licence at the same time during that session.



The results can be exported from iPassport using the ‘Export List’ option, in the top right corner of the results area. The export is prepared in the background rather than downloaded straight away: a progress window opens while the file is generated, and a download link appears in that window once the file is ready. The exported file is a CSV, which can be opened in Excel™.


Nothing needs to be entered in the ‘User Name’ field to retrieve the details for all users. Leaving the field empty, which is how the tab opens, returns every user’s activity; entering a space has the same effect but is not necessary. Note that the activity of the iPassport support login is always excluded from the results.


Suppressed Emails tab


This tab is visible to Site Admins, Facility Admins, users who have the Administration Editor role and the iPassport support team, and also to any user whose role carries the permission “Users:Remove Suppressed Email Address”.


Note
SITE ADMINS
It is strongly recommended that each account has at least one Site Admin.
They are automatically granted access to all areas of iPassport, regardless of their user group membership. This includes privileges no one else has, like accessing private records whose owner has left the organisation and which would otherwise be locked. Site Admins can also save the day if an OU gets accidentally detached from user groups in such a way that no one else can see it.
The first Site Admin can only be appointed by the iPassport support team (support@genialcompliance.com).
This person can then add other users to the list of Site Admins.


If a user reports they are not receiving emails from iPassport, this is probably the first place to look.



iPassport’s mail server monitors email traffic and the provider is entitled to disable our service if emails sent to a given address are repeatedly bounced. To prevent this from happening, the system internally catches bounced emails and suppresses further emails to that address. This gives users the opportunity to investigate the problem and un-suppress the email address when the issue is resolved.


Note
AUTOMATIC RETRIES
A suppressed address does not always have to be reinstated by hand. iPassport retries a suppressed address automatically on an increasing delay — after 15 minutes, then after 12 hours, then after 2 days — for up to three attempts.
If the underlying problem has cleared by the time one of those attempts is made, the address leaves the list without any administrator action. If emails to it are still refused, it is suppressed again and the next, longer delay applies.


Emails can be refused by the user’s email system for many reasons. There might have been a problem with the recipient’s mail server, or their inbox was full, or because the email address entered in iPassport was incorrect or invalid. An address is also suppressed when an iPassport email sent to it is reported as spam or abuse, which needs a different remedy from a bounce because the recipient has actively marked the message as unwanted.


The reason for each entry is shown in the ‘Suppression Reason’ column, either “A bounced iPassport email was detected from this address.” or “An iPassport email was flagged as spam / abuse from this address.” Alongside it, the list shows the ‘Email Address’, the date it has been ‘Suppressed Since’, the ‘User(s)’ holding that address, and the ‘Actions’ column.


Any address listed in this tab will not receive emails from iPassport. The list is not, however, a complete record of every suppressed address: it shows only the suppressed addresses belonging to active users of the current account. An address belonging to an inactive user, or to no user record at all, is still blocked but is not displayed here.


To reinstate an email address, use the trash/bin icon in the Actions column. The icon is only shown to users who are allowed to remove a suppressed address, which is governed by the permission “Users:Remove Suppressed Email Address”. Site Admins and the iPassport support team always satisfy that check, but they are not the only ones who can do it: any role granted that permission can reinstate an address as well.


Clicking the icon schedules the removal rather than completing it immediately. The row shows ‘Deleting..’ in place of the icon, and a background process, which runs every five minutes, then takes the address off the suppression list so that emails can be sent to that recipient again. There may therefore be a short delay before the address disappears from the list.


Reports tab


Another place to investigate why a user is not receiving certain emails is in their personal preferences. The ‘Personal Preferences’ area (My Profile > Preferences) allows a user to disable email notifications generated by different events in the system. It is not possible to change another user’s personal preferences but administrators can view them.


The permission, “User Accounts:Preference Report” is required for the tab to be visible.


The report, “User preferences” can be generated to obtain a list of the personal preferences of every user in the account.


This report is also an easy way to produce a list of all the users in the account. Inactive users are also listed and labelled as such.


Next Step:

The next article covers User Importer


Previous Step:

The previous article covers Inactivating/Reactivating Users

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article