Changes for page Benutzerverwaltung
Last modified by Sabrina V. on 2026/10/06 09:56
From version 2.1
edited by Sabrina V.
on 2026/07/23 08:41
on 2026/07/23 08:41
Change comment:
There is no comment for this version
To version 7.1
edited by Sabrina V.
on 2026/10/06 09:56
on 2026/10/06 09:56
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,50 +1,50 @@ 1 1 {{aagon.floatingbox/}} 2 2 3 -In the //User Management// section, you can create, edit, and delete users and user groups. This allows you, for example, to set up users for branch offices to better distribute tasks within ACMP. It also lets you use user group and user rights within User Management to control who can view specific solutions inACMPand perform certain actions.3 +In the //User Management// section, you can create, edit, and delete users and user groups. This allows you, for example, to set up users for branch offices to better distribute tasks within acmp. It also lets you use user group and user rights within User Management to control who can view specific solutions in acmp and perform certain actions. 4 4 5 5 6 -= Rights and Permissions in ACMP=6 += Rights and Permissions in acmp = 7 7 8 -Rights management in ACMPis an indirect part of user management. The control of rights for users and groups consists of two components: basic rights and component-specific permissions.8 +Rights management in acmp is an indirect part of user management. The control of rights for users and groups consists of two components: basic rights and component-specific permissions. 9 9 10 10 |=(% style="width: 437px;" %)Components of Rights Management|=(% style="width: 1035px;" %)Description 11 11 |(% style="width:437px" %)Fundamental Rights|(% style="width:1035px" %)((( 12 -Basic rights refer to the rights that are assigned to users and groups directly during creation or in user management and that apply across the entire ACMP Console. Using these rights, you can, for example, specify whichACMPSolutions a user is allowed to view and which actions they are permitted to perform within a solution. For more info, you can jump to the section on [[Rights of User>>doc:||anchor="HRechtedesBenutzersfestlegen"]].12 +Basic rights refer to the rights that are assigned to users and groups directly during creation or in user management and that apply across the entire acmp Console. Using these rights, you can, for example, specify which acmp Solutions a user is allowed to view and which actions they are permitted to perform within a solution. For more info, you can jump to the section on [[Rights of User>>doc:||anchor="HManagingUsersandGroupsinACMP"]]. 13 13 ))) 14 14 |(% style="width:437px" %)Component-Specific Permissions|(% style="width:1035px" %)Component-specific permissions allow you to specify, for individual system components and elements - such as reports, Client Commands, or folders - which users are allowed to view and, if applicable, edit each component. These permissions are managed through individual access lists for each component. For more information on permissions, see the “Access Lists” section. 15 15 16 16 == Default Users and Groups == 17 17 18 -Closely linked to the basic rights and specific permissions are the default user //ADMINISTRATOR// and the default group //Privileged users//. The //ADMINISTRATOR// user account has all existing rights and permissions in the ACMP Console and cannot be edited or deleted. The “Privileged users” group, on the other hand, is a default group that cannot be edited through general user management. This group is created dynamically and individually for each access list inACMP. This means that this group includes all users who have the basic right to view the respective solution containing the specific access list. Thus, the //Privileged users// group can be used to control which individual components users within a specific solution can view and use. For more information on working with access lists, see the section “Access Lists inACMP.”18 +Closely linked to the basic rights and specific permissions are the default user //ADMINISTRATOR// and the default group //Privileged users//. The //ADMINISTRATOR// user account has all existing rights and permissions in the acmp Console and cannot be edited or deleted. The “Privileged users” group, on the other hand, is a default group that cannot be edited through general user management. This group is created dynamically and individually for each access list in acmp. This means that this group includes all users who have the basic right to view the respective solution containing the specific access list. Thus, the //Privileged users// group can be used to control which individual components users within a specific solution can view and use. For more information on working with access lists, see the section “Access Lists in acmp.” 19 19 20 -= Managing Users and Groups in ACMP=20 += Managing Users and Groups in acmp = 21 21 22 22 In the overview, you'll see the two tabs, “Users” and “Groups,” under which the respective items are displayed. When you first open the view, the focus is on the users. 23 23 24 -[[User Management>>image:68_System_Benutzerverwaltung Übersicht_1821.png||alt="63_System_Benutzerverwaltung_1696.png" data-xwiki-image-style-alignment="center"]] 24 +[[User Management>>image:68_System_Benutzerverwaltung Übersicht_1821.png||alt="63_System_Benutzerverwaltung_1696.png" data-cmp-info="10" data-xwiki-image-style-alignment="center"]] 25 25 26 -Depending on which option you selected ([[Users>>doc:||anchor="H Benutzerverwalten"]] or [[Groups>>doc:||anchor="HGruppenverwalten"]]), the commands in the ribbon bar will change. However, you can [[import AD users>>doc:||anchor="HActiveDirectory-Benutzerimportieren"]] from either tab at any time. In the left pane, you’ll see a list of all created users, from which you can, for example, see at a glance what roles they have been assigned and whether multi-factor authentification (MFA) is activated. On the right side is the detail view for the currently selected user.26 +Depending on which option you selected ([[Users>>doc:||anchor="HManageUsers"]] or [[Groups>>doc:||anchor="HManageGroups"]]), the commands in the ribbon bar will change. However, you can [[import AD users>>doc:||anchor="HImportActiveDirectoryUsers"]] from either tab at any time. In the left pane, you’ll see a list of all created users, from which you can, for example, see at a glance what roles they have been assigned and whether multi-factor authentification (MFA) is activated. On the right side is the detail view for the currently selected user. 27 27 28 28 Legend 29 29 30 30 |(% style="width:278px" %)**Symbol**|(% style="width:1414px" %)**Description** 31 31 |(% style="width:278px" %)((( 32 -[[image:1730896286452-269.png]] 32 +[[image:1730896286452-269.png||data-cmp-info="10"]] 33 33 34 34 Helpdesk 35 35 )))|(% style="width:1414px" %)The user can be a ticket editor 36 36 |(% style="width:278px" %)((( 37 -[[image:1730896286453-120.png]] 37 +[[image:1730896286453-120.png||data-cmp-info="10"]] 38 38 39 39 Tenants 40 40 )))|(% style="width:1414px" %)The user can view and manage all Clients regardless of their client relationships 41 41 |(% style="width:278px" %)((( 42 -[[image:1730896286453-510.png]] 42 +[[image:1730896286453-510.png||data-cmp-info="10"]] 43 43 44 44 Multi-factor authentifcation 45 45 )))|(% style="width:1414px" %)Multi-factor authentification is activated for the user 46 46 |(% style="width:278px" %)((( 47 -[[image:1730896286454-100.png]] 47 +[[image:1730896286454-100.png||data-cmp-info="10"]] 48 48 49 49 Multi-factor authentifcation 50 50 )))|(% style="width:1414px" %)Multi-factor authentification is enforced for the user and must be set up during the next login, if it has not already been done (see Use Case: Enforcing Multi-Factor Authentication for Another User) ... ... @@ -82,21 +82,21 @@ 82 82 * It will not be possible to assign tickets and comments to a contact in the Helpdesk 83 83 * Problems may occur when importing contacts using the Contacts Adapter 84 84 85 -Finally, set a password for the ACMP Console. You can also set a password directly for using the web interface. Use the //Password Strength// view to check how suitable and strong your chosen password is.85 +Finally, set a password for the acmp Console. You can also set a password directly for using the web interface. Use the //Password Strength// view to check how suitable and strong your chosen password is. 86 86 87 -[[Set User Properties>>image:67_Benutzerverwaltung_Benutzereigenschaften_904.png||alt="Benutzerverwaltung_Gruppenzuweisung.png"]] 87 +[[Set User Properties>>image:67_Benutzerverwaltung_Benutzereigenschaften_904.png||alt="Benutzerverwaltung_Gruppenzuweisung.png" data-cmp-info="10"]] 88 88 89 89 90 90 91 91 **Assign Groups** 92 92 93 -In the second step, specify the group membership. In most cases, [[groups>>doc:||anchor=" #Gruppen"]] have different rights. A user can be assigned to multiple groups. There is no requirement to assign a user to a group. Some groups are already provided when you installACMP(including //AD Login//, //Full access//, and //Secured by MFA//).93 +In the second step, specify the group membership. In most cases, [[groups>>doc:||anchor="HManageGroups"]] have different rights. A user can be assigned to multiple groups. There is no requirement to assign a user to a group. Some groups are already provided when you install acmp (including //AD Login//, //Full access//, and //Secured by MFA//). 94 94 95 95 {{aagon.warnungsbox}} 96 96 For security reasons, it is not recommended to assign a user to multiple groups. Instead, you can, for example, create a separate group for the user. 97 97 {{/aagon.warnungsbox}} 98 98 99 -[[Mapping the user to one or more groups>>image:67_Benutzerverwaltung_Gruppenzuweisung.png||alt="Benutzerverwaltung_Gruppenzuweisung.png"]] 99 +[[Mapping the user to one or more groups>>image:67_Benutzerverwaltung_Gruppenzuweisung.png||alt="Benutzerverwaltung_Gruppenzuweisung.png" data-cmp-info="10"]] 100 100 101 101 102 102 ... ... @@ -105,27 +105,26 @@ 105 105 In the third step, you can set the rights of the user. If you assigned the user to a group in the prior step, the following page will display which rights the user will have. If you did not specify a group, you can set the rights of the user individually. To do this, select the solutions that should be visible to the user. Once you have selected a solution, you can specify in the field on the right which rights the user should have for that solution. 106 106 107 107 108 -[[Enable visibility for solutions and assign user permissions>>image:68_Benutzerverwaltung_Rechte des Benutzers_1078.png||alt="System_Benutzerverwaltung_NeuerBenutzer3" data-xwiki-image-style-alignment="center"]] 108 +[[Enable visibility for solutions and assign user permissions>>image:68_Benutzerverwaltung_Rechte des Benutzers_1078.png||alt="System_Benutzerverwaltung_NeuerBenutzer3" data-cmp-info="10" data-xwiki-image-style-alignment="center"]] 109 109 110 110 111 111 112 112 **Select Roles and Tenants** 113 113 114 -Now define roles and tenants for the user. You can specify whether the user should be assigned a Helpdesk role, which would allow them to become a ticket editor. You can also specify whether the user can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610. ACMP-Solutions.System.Einstellungen.ACMPServer.WebHome||anchor="HMandantenfE4higkeit"]] inACMP, you must grant the user access to all tenants or at least selected tenants.114 +Now define roles and tenants for the user. You can specify whether the user should be assigned a Helpdesk role, which would allow them to become a ticket editor. You can also specify whether the user can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.Mandantenfähigkeit in ACMP.WebHome]] in acmp, you must grant the user access to all tenants or at least selected tenants. 115 115 116 116 (% class="box warningmessage" %) 117 117 ((( 118 -[[image:https://doc.aagon.com/bin/download/XWiki/Aagon%20Warnungsbox/WebHome/Warning.svg||alt="Warning" height="32" width="32"]] **Achtung: ** 118 +[[image:https://doc.aagon.com/bin/download/XWiki/Aagon%20Warnungsbox/WebHome/Warning.svg||alt="Warning" data-cmp-info="10" height="32" width="32"]] **Achtung: ** 119 119 120 -If you do not select a tenant, the new user will not be able to log in to the ACMP Console later.120 +If you do not select a tenant, the new user will not be able to log in to the acmp Console later. 121 121 ))) 122 122 123 -[[Define Roles and Tenants>>image:Benutzerverwaltung_Rollen und Mandanten.png]] 123 +[[Define Roles and Tenants>>image:Benutzerverwaltung_Rollen und Mandanten.png||data-cmp-info="10"]] 124 124 125 125 126 +**Set acmp Contact** 126 126 127 -**Set ACMP Contact** 128 - 129 129 In the final step, you can assign an existing contact from the Helpdesk to the user or create a new contact for the user 130 130 131 131 {{aagon.infobox}} ... ... @@ -152,10 +152,8 @@ 152 152 153 153 In the //Groups// tab, you can add new groups and edit, delete, or duplicate existing groups. 154 154 155 -[[Group Overview in User Management>>image:68_Benutzerverwaltung_Gruppen Übersicht_1660.png||alt="67_Benutzerverwaltung_Gruppen Übersicht_1660.png"]] 154 +[[Group Overview in User Management>>image:68_Benutzerverwaltung_Gruppen Übersicht_1660.png||alt="67_Benutzerverwaltung_Gruppen Übersicht_1660.png" data-cmp-info="10"]] 156 156 157 - 158 - 159 159 === **Add Group** === 160 160 161 161 Click the //Add// button on the ribbon bar to create a new group. In the wizard that opens, first enter a name and, optionally, a description for the group. ... ... @@ -168,7 +168,7 @@ 168 168 169 169 Next, in the third step, specify the rights of group. To do this, first select the solutions that should have visibility to the group. Once you’ve selected a solution, you can specify in the right-hand field what rights the group members should have for that solution. 170 170 171 -[[image:68_System_Benutzerverwaltung Gruppenrechte_965.png||alt="System_Benutzerverwaltung_NeueGruppe1" data-xwiki-image-style-alignment="center"]] 168 +[[image:68_System_Benutzerverwaltung Gruppenrechte_965.png||alt="System_Benutzerverwaltung_NeueGruppe1" data-cmp-info="10" data-xwiki-image-style-alignment="center"]] 172 172 173 173 (% style="text-align:center" %) 174 174 Enable visibility for solutions and assign group permissions ... ... @@ -178,28 +178,27 @@ 178 178 179 179 **Select Roles and Tenants** 180 180 181 -Now define the roles and tenants for the group. You can specify whether members of this group should be assigned a Helpdesk role, which would allow them to become ticket editors. A member of this group can thus act as a Helpdesk agent to create, edit, and process tickets. You can also specify whether members of this group can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610. ACMP-Solutions.System.Einstellungen.ACMPServer.WebHome||anchor="HMandantenfE4higkeit"]] inACMP, you must grant the user access to all tenants or at least selected tenants.178 +Now define the roles and tenants for the group. You can specify whether members of this group should be assigned a Helpdesk role, which would allow them to become ticket editors. A member of this group can thus act as a Helpdesk agent to create, edit, and process tickets. You can also specify whether members of this group can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.Mandantenfähigkeit in ACMP.WebHome]] in acmp, you must grant the user access to all tenants or at least selected tenants. 182 182 183 183 184 - 185 185 **Active Directory Group Mapping** 186 186 187 -This step is used to map users in an Active Directory group to the ACMPgroup you are currently creating. This allows you to manage users exclusively through AD, rather than having to manually create all users inACMPagain. To use this function effectively, you must specify a login group in the platform configuration that includes all users authorized to access theACMP(see [[Login>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HActiveDirectoryLogin"]]).183 +This step is used to map users in an Active Directory group to the acmp group you are currently creating. This allows you to manage users exclusively through AD, rather than having to manually create all users in acmp again. To use this function effectively, you must specify a login group in the platform configuration that includes all users authorized to access the acmp (see [[Login>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HActiveDirectoryLogin"]]). 188 188 189 189 {{aagon.infobox}} 190 190 If you do not want to use this function, you can skip this step and finish creating the group. 191 191 {{/aagon.infobox}} 192 192 193 -Now configure the group so that an AD group is assigned to it. This ensures that a user in the AD group is automatically created in ACMPupon their first login and assigned to this group. If the user already exists, they will be assigned to this group if they have not already been. Similarly, you can manually synchronize users using the //Import all new AD users from the AD access group in user management// function, which will also removeACMPUsers from the group if they are no longer part of the assigned AD group. However,ACMPusers are not automatically deleted.ACMPusers can also continue to be created manually and assigned to the group; as a result, they will not be included in the synchronization when a manual synchronization is performed using the aforementioned function.189 +Now configure the group so that an AD group is assigned to it. This ensures that a user in the AD group is automatically created in acmp upon their first login and assigned to this group. If the user already exists, they will be assigned to this group if they have not already been. Similarly, you can manually synchronize users using the //Import all new AD users from the AD access group in user management// function, which will also remove acmp Users from the group if they are no longer part of the assigned AD group. However, acmp users are not automatically deleted. acmp users can also continue to be created manually and assigned to the group; as a result, they will not be included in the synchronization when a manual synchronization is performed using the aforementioned function. 194 194 195 195 (% style="text-align:center" %) 196 -[[image:XWiki.Images.WebHome@system_benutzerverwaltung_neuegruppe2.png||alt="System_Benutzerverwaltung_NeueGruppe2" height="401" width="327"]] 192 +[[image:XWiki.Images.WebHome@system_benutzerverwaltung_neuegruppe2.png||alt="System_Benutzerverwaltung_NeueGruppe2" data-cmp-info="10" height="401" width="327"]] 197 197 Add an Active Directory group 198 198 199 -To assign a corresponding AD group to this ACMPgroup, click //Add// and, in the new window, select the domain in which the group to be assigned is located. Enter a group name or part of it, and click //Check Name// to display all matching groups. Select the group you want to map. You can map multiple AD groups to a singleACMPgroup.195 +To assign a corresponding AD group to this acmp group, click //Add// and, in the new window, select the domain in which the group to be assigned is located. Enter a group name or part of it, and click //Check Name// to display all matching groups. Select the group you want to map. You can map multiple AD groups to a single acmp group. 200 200 201 201 {{aagon.infobox}} 202 -To enable the selection of domains via the dialog box, a user with domain read permissions must be entered in the ACMPsettings (see login).198 +To enable the selection of domains via the dialog box, a user with domain read permissions must be entered in the acmp settings (see login). 203 203 {{/aagon.infobox}} 204 204 205 205 ... ... @@ -215,7 +215,7 @@ 215 215 Exit your work by clicking //Done// to create a group. 216 216 217 217 218 -[[Configuration Options for Multi-Factor Authentication>>image:67_Benutzerverwaltung_Gruppe hinzufügen Multifaktor-Authentifizierung_mit Haken_810.png]] 214 +[[Configuration Options for Multi-Factor Authentication>>image:67_Benutzerverwaltung_Gruppe hinzufügen Multifaktor-Authentifizierung_mit Haken_810.png||data-cmp-info="10"]] 219 219 220 220 {{aagon.infobox}} 221 221 See the “Enforcing multi-factor authentification for a user” use case to learn how to set this up for other users. ... ... @@ -255,15 +255,15 @@ 255 255 256 256 === Reset multi-factor authentification for a User === 257 257 258 -To reset multi-factor authentification for a user, you can use the button of the same name in the ribbon bar ([[image:1730896831843-996.png]]). Confirm your entry, and all factors for the selected user’s multi-factor authentification will be deleted. The user password remains unchanged. If mandatory authentication has been configured for the user, the user will be required to set up authentication automatically upon their next login. 254 +To reset multi-factor authentification for a user, you can use the button of the same name in the ribbon bar ([[image:1730896831843-996.png||data-cmp-info="10"]]). Confirm your entry, and all factors for the selected user’s multi-factor authentification will be deleted. The user password remains unchanged. If mandatory authentication has been configured for the user, the user will be required to set up authentication automatically upon their next login. 259 259 260 260 261 261 262 262 = Import Active Directory Users = 263 263 264 -In ACMP, one or more AD groups can be assigned to a group, linked by “or.” A mapping is displayed by a corresponding icon. All members of these groups can log in to theACMP Console and have the rights assigned to their group. A prerequisite for this is that they are also members of the respective access group specified under [[AD Login>>doc:||anchor="HActiveDirectory-Anmeldung"]]. Manually adding users is not necessary in this case, but it remains possible, allowing users to be managed entirely within Active Directory.260 +In acmp , one or more AD groups can be assigned to a group, linked by “or.” A mapping is displayed by a corresponding icon. All members of these groups can log in to the acmp Console and have the rights assigned to their group. A prerequisite for this is that they are also members of the respective access group specified under [[AD Login>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HActiveDirectoryLogin"]]. Manually adding users is not necessary in this case, but it remains possible, allowing users to be managed entirely within Active Directory. 265 265 266 -If a user logs in this way, the system automatically adds them to the ACMPDatabase. Alternatively, all users can be manually imported into the database using the //Import all new AD users from the AD access group into the database// function. This does not involve user synchronization, so existing users are neither imported into AD nor deleted from it. Users who have been deleted from Active Directory or removed from a group are not deleted from theACMPDatabase, but are merely removed from the correspondingACMPgroups.262 +If a user logs in this way, the system automatically adds them to the acmp Database. Alternatively, all users can be manually imported into the database using the //Import all new AD users from the AD access group into the database// function. This does not involve user synchronization, so existing users are neither imported into AD nor deleted from it. Users who have been deleted from Active Directory or removed from a group are not deleted from the acmp Database, but are merely removed from the corresponding acmp groups. 267 267 268 268 {{aagon.infobox}} 269 269 Disabled users are not included in the user import. ... ... @@ -270,5 +270,5 @@ 270 270 {{/aagon.infobox}} 271 271 272 272 (% style="text-align:center" %) 273 -[[image:XWiki.Images.WebHome@hmfile_hash_3bb9c266.png||alt="9.3 - Loginprozess" height="542" width="715"]] 269 +[[image:XWiki.Images.WebHome@hmfile_hash_3bb9c266.png||alt="9.3 - Loginprozess" data-cmp-info="10" height="542" width="715"]] 274 274 Flowchart of the Login Process

