# User Management Lifecycle | Endpoint Central MSP Last Updated On: 11 Oct 2026 30 minutes read ## Overview Effective user management is essential for maintaining system security and ensuring appropriate access control. This document outlines the complete lifecycle of user accounts, detailing their creation, management, and role-based access within the system. User accounts, which can be either local accounts or Active Directory accounts, are created within the Central Server to grant access to endpoints, custom groups, and remote offices. Roles define a set of permissions that determine what actions a user can perform within the system and outline the scope of which computers or devices the user will be allowed to manage. Each user is assigned a role, which dictates their level of access. This document covers the management of **Endpoint Central MSP web console** user accounts (technicians and administrators). If you are looking to configure local accounts or domain accounts on managed endpoint machines, refer to the [User Management Configuration](https://www.manageengine.com/desktop-management-msp/help/configuration-management/managing_windows_local_users-computer.html) page. ## Prerequisites for User Creation A configured mail server is essential for user account creation and user account-related notifications, such as password resets, account activation, and security alerts. Proper SMTP settings must be in place to ensure seamless email communication. Refer to the Mail Server Configuration [document](https://www.manageengine.com/desktop-management-msp/help/server/configure-O365-mail-server-settings.html) for detailed setup instructions. ## Local User Creation 1. Navigate to the **Admin tab** and select *User* under User Administrator. 2. Choose **Local Authentication** as the authentication type. 3. Enter a **User Name** and manually enter the user’s email address. 4. Select the **Role** from the drop-down list, which includes both predefined and user-defined roles. 5. Enter the user's **Contact number** if necessary. 6. Choose a **language** from the drop-down list for multi-language support; refer to the supported languages document. 7. Define the user's **scope** by specifying which computers they need to manage; refer to the [Scope of the User](https://www.manageengine.com/desktop-management-msp/help/access-management/usermanagement-lifecycle.html#scope-of-the-user) section for detailed instructions. 8. Click on **Add User**. ![Screenshot of local user creation form in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-1.png) ## Active Directory (AD) User Creation 1. Navigate to the **Admin tab** and select *User* under User Administrator. 2. Choose **Active Directory Authentication** as the authentication type. 3. Select a **Domain** in the **Domain Name** field; refer to the document on how to add a domain. 4. Choose a **username** fetched from Active Directory (AD). 5. The user’s **email address** will be automatically fetched from Active Directory if available. If not, manually enter the email address. 6. Select the **Role** from the drop-down list, which includes both predefined and user-defined roles. 7. Enter the user's **Contact number** if necessary. 8. Choose a **language** from the drop-down list. 9. Define the user's **scope** by specifying which computers they need to manage. 10. Click on **Add User**. ![Screenshot of AD user creation form in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-2.png) > **Note:** If you want to enable login using SAML authentication, you must create either a **Local User** or an **AD User**. For detailed steps, refer to the [SAML Authentication documentation](https://www.manageengine.com/desktop-management-msp/help/user-management/saml-authentication-with-sso.html). ## Scope of the User A scope defines which computers and devices a user can see and manage. You assign a scope when you create or modify a user. Each user has two scope dimensions: 1. **Computers to be Managed:** Controls which endpoint computers the user can see and act on. 2. **Devices to be Managed:** Controls which mobile devices the user can manage (MDM). A role and a scope are different. The role controls what the user can do, and the scope controls which computers and devices those actions apply to. You must configure both. ### Computers to be Managed You can assign one of the following computer scope types to a user. #### **All Computers** The user has access to all computers managed in the Endpoint Central MSP server. This is the broadest scope and is appropriate for administrators and senior technicians who need visibility across the entire environment. ![All Computers scope selection](https://cdn.manageengine.com/sites/meweb/images/desktop-management-msp/help/access-management/umlc-3.webp) #### **Static Unique Groups** The user has access only to the computers in the custom groups that you designate. Only Static Unique groups are available here. If a custom group is not marked as unique, it does not appear in the scope selection list. For details on creating a Static Unique group, refer to [Static Unique Custom Groups](https://www.manageengine.com/desktop-management-msp/help/custom-groups/static-unique-custom-group.html). Static Unique groups are best used when you need to manage devices based on teams, departments, or functions within a location. Examples: - Static Unique group: Finance Team - Static Unique group: Product Engineering - Static Unique group: Customer Support ![Static Unique Groups scope selection](https://www.manageengine.com/products/desktop-central/images/umlc-4.png) > **Note:** The user's access follows the group's membership. If a computer is removed from a Static Unique group, the scoped user immediately loses access to that computer, even if the computer still exists elsewhere in the console. Computers added to the group become available to the user automatically. #### **Remote Office** The user has full access to all computers in a designated Remote Office. Remote Offices are ideal when your organization operates across multiple locations or branch offices and you want to delegate management of each location to a local IT team. For details on creating Remote Offices, refer to [Managing Computers in WAN](https://www.manageengine.com/products/desktop-central/help/configuring_desktop_central/managing_computers_wan.html). Examples: - Remote Office: New York, IT Team - Remote Office: London, Finance Team - Remote Office: Mumbai, Sales Team ![Remote Office scope selection](https://www.manageengine.com/products/desktop-central/images/umlc-5.png) > **Note:** A user scoped to a Remote Office can manage all computers currently assigned to it. If a computer is moved to a different Remote Office, the user loses access to it automatically. ### Devices to be Managed You can control which mobile devices (MDM-enrolled) a user can manage: - **All Devices:** The user can manage all mobile devices enrolled in the console. ![All Devices scope selection](https://www.manageengine.com/products/desktop-central/images/umlc-6.png) - **Device Groups:** The user can manage only the devices in the device groups that you designate. ### Scope Quick Reference The following table shows how different combinations of computer scope and device scope affect what each user can manage. The worked scenarios that follow refer to the same users. | User | Computer Scope | Device Scope | Access Effect | |---|---|---|---| | A | All Computers | All Devices | Full access to all computers and all mobile devices in the console. | | B | Remote Office 1 | All Devices | Can manage all computers in Remote Office 1 and all mobile devices. | | C | All Remote Offices | Device Group A | Can manage all computers across all Remote Offices, but only devices in Group A. | | D | Static Unique group: Finance Team | Device Group X | Can manage only computers in the Finance Team group and devices in Group X. | | E | Remote Office 1 | Device Group Y | Can manage computers in Remote Office 1 and devices in Group Y only. | | F | Remote Office 1 & Remote Office 2 | Device Group Z | Can manage computers in both Remote Offices, and only devices in Group Z. | ### Worked Scenarios Scenarios A1 to A4 cover computer scope. Scenarios B1 to B3 cover device scope (MDM). #### Scenario A1: Scope by Static Unique group - **User D** has the scope Static Unique group: Finance Team (10 computers). - **User A** has the scope All Computers. - **How it works:** User D can push policies only to the 10 computers in the Finance Team group. If a computer is moved out of the group, User D immediately loses access to it, even if it remains in the console. User A is unaffected and continues to see all computers. #### Scenario A2: Group membership expands - The admin adds 5 more computers to the Finance Team group. - **How it works:** User D automatically sees and can manage the 5 new computers. No change to User D's scope is needed. #### Scenario A3: Scope by Remote Office - **User B** has the scope Remote Office 1 (London). - **User A** has the scope All Computers. - **How it works:** User B can manage all computers currently assigned to the London Remote Office. If a computer is reassigned to the Mumbai Remote Office, User B loses access to it. User A continues to see all computers across all Remote Offices. #### Scenario A4: Multiple Remote Offices assigned to one user - **User F** has the scope Remote Office 1 (London) and Remote Office 2 (New York). - **How it works:** User F can manage computers in both London and New York, but cannot see computers in the Mumbai Remote Office. If a computer moves from London to Mumbai, User F loses access to it. For MDM, User F can manage only the mobile devices in Device Group Z. #### Scenario B1: Scope by Device Group - **User A** has the scope All Devices. - **User D** has the scope Device Group X only. - **How it works:** User A can manage every enrolled mobile device. User D can manage only the devices in Group X. A configuration that targets Group Y is not visible to User D. If User D needs to manage Group Y, the admin must update User D's scope. #### Scenario B2: Device Group is restructured - Device Group X is split into Group X1 and Group X2. - **How it works:** Unless the admin updates User D's scope to include X1 and X2, User D manages only the devices that remain in the original Group X. User A is unaffected and continues to manage all devices. #### Scenario B3: Configuration targets two device groups - A configuration is created that targets both Device Group X and Device Group Y. - **How it works:** User D, who is scoped only to Group X, can see the configuration but may not be able to edit it, because the configuration also applies to Group Y, which is outside User D's scope. > **Note:** Only Administrator Role users have full access to the User Management console. ## User Management Actions Administrator users can modify, delete, reset passwords, disable accounts, and regenerate QR codes for users using the Action button. ### 1. Modify User Administrator users can modify, add, and remove user details, as well as define scope. #### How to Modify User? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. On the user page, click the three-dotted **action button** in the action column. 4. Select Modify. The user details page will open where you can modify, add, and remove details. ![Screenshot showing modify user details in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-7.png) #### Modifying AD User - If it is an AD user, you can modify the domain name. - **Note:** The username cannot be modified. - Modify the role, email, contact number, and language. - Define the user's scope by specifying which computers and devices they need to manage. #### Modifying Local User - Modify the role, email, contact number, and language. - **Note:** The username cannot be modified. - Define the user's scope by specifying which computers and devices they need to manage. #### Convert User Authentication Type - You can change an AD user to a local user by modifying the authentication type. - The user will then receive a password creation link via email, allowing them to log in as a local user. - You can also change a local user to an AD user by modifying the authentication type. - **Note:** The same username must be present in Active Directory. - If **Two-Factor Authentication (TFA)** is enabled, switching the authentication type will require the user to re-scan the QR code to reconfigure their authenticator app. Refer to the [Secure Authentication](https://www.manageengine.com/desktop-management-msp/help/user-management/secureauthentication.html) documentation for TFA setup details. ### 2. Logon Details Administrator users can view the logon details of users to monitor their logon activities. #### How to view Logon Details? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. On the user page, click the three-dotted **action button** in the action column. 4. Select Logon Details. 5. A popup will display the logon details of the last 10 activities. ![Screenshot of user logon details popup in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-9.png) ![Alternate view of user logon details in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-8.png) ### 3. Delete User Removing a user from the Central Server will revoke their access. Deletion permanently removes personal information such as email and contact number from notifications. If API keys have been generated, those integrations will be disabled unless new keys are generated prior to deletion. #### How to Delete User? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. Click the three-dotted **action button** in the action column. 4. Select Delete User. 5. In the Confirmation User Deletion Popup, optionally check the box to provide alternative contact details for replacement. 6. Remove any secondary contact details used for notifications. 7. Click **Delete User** to confirm deletion. ![Screenshot of delete user confirmation popup in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-10.png) ### 4. Reset Password The following steps describe the password reset process for a technician or Administrator using the Central Server web console. Refer to the [User Password Reset Guide](https://www.manageengine.com/desktop-management-msp/help/desktop-central/reset-desktop-central-password-how-to.html). > **Note:** **EC Cloud Note:** If the **Reset Password** option is not visible for a user, the account may be in a pending-invite state. Resend the invitation or complete the admin transfer process. Refer to the [EC Cloud FAQ](https://www.manageengine.com/products/desktop-central/cloud/frequently-asked-questions.html) for details on the admin-transfer and invite flow. #### How to Reset Password? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. Click the three-dotted **action button** in the action column. 4. Select Reset Password. 5. A mail will be sent to the user with instructions and a link to reset the password. 6. The password reset link will expire in 30 minutes. 7. If the email is not delivered due to mail server issues, a “Send link manually” option will appear in the Remarks column for that user. 8. The Administrator can copy and manually send the password reset link. ![Screenshot of password reset confirmation in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-11.png) ### 5. Disable User Disabling a user account prevents login until reactivation and disrupts any enabled integrations. This action helps manage inactive accounts. For inactivity-based disabling, refer to the User Account Policy. #### How to Disable User Account? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. Click the three-dotted **action button** in the action column. 4. Select Disable Account. 5. In the confirmation popup, select "Yes, disable." ![Screenshot of disable account confirmation popup in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-12.png) ### 6. Regenerate QR Code If secure authentication is enabled via an Authenticator app, the Administrator can regenerate a QR code to set up OTP on a new device if the current one is lost or the app is accidentally removed. #### How to Regenerate QR Code? 1. Navigate to the **Admin tab**. 2. Select **User** under User Administrator. 3. Click the three-dotted **action button** in the action column. 4. Select Regenerate QR code. 5. In the confirmation popup, select "Regenerate QR code." ![Screenshot of regenerate QR code confirmation in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-13.png) ## Personalization The Personalize menu allows users to customize their account settings for a tailored experience. It enables session management, time zone and format settings, language preferences, and password updates for better security and usability. ### How to Access Personalization? 1. Log in to the web console. 2. Click the user profile icon located at the top-right corner, then select **Personalize**. ![Screenshot of personalization options in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-14.png) ### Change Session Expiration 1. Under the **General Settings** tab, locate the **Session Expiration** dropdown and select a duration. 2. Go to the **Choose Time Zone** dropdown and select the appropriate time zone. 3. Locate the **Choose Time Format** dropdown and select the desired date and time format. 4. Find the **Display Language** dropdown and choose your preferred language. 5. Click the **Save** button to apply the changes. ### Changing Your Password 1. Open the **Personalize** window and click the **Change Password** tab. 2. Enter your current password in the **Old Password** field. 3. Type your new password in the **New Password** field, ensuring it meets the policy requirements. 4. Re-enter the new password in the **Confirm Password** field for verification. 5. Click **Save** to update your password or **Close** to cancel. Refer to the detailed password reset document for more information. ![Screenshot of change password interface in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-15.png) ## Active Session Users can log in to multiple sessions simultaneously on different browsers. ### How to view Active User Sessions? 1. Navigate to the **Admin tab**. 2. Click the user profile icon located at the top-right corner. 3. Select **Active Session**. ![Screenshot of active user sessions interface in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-16.png) The Administrator can configure session expiry settings in the **User Account Policy**; refer to the related link. ## Notifications The Notification feature allows the Administrator to receive alerts when users perform various operations. To receive these alerts, the Administrator's email address(es) must be configured. ### How to Configure Notifications? 1. Log in to the Central Server. 2. Navigate to the **Admin tab**. 3. Select **User** under User Administrator. 4. On the user page, select **Notifications**. 5. Configure notifications for the events as shown in the image below: ![Screenshot of notification configuration events in Central Server](https://www.manageengine.com/products/desktop-central/images/umlc-17.png) 6. **Administrator's E-mail Address:** Enter one or more email addresses. 7. **Mobile App Notification for Administrator:** Use the dropdown labeled **Select Administrator(s) to be notified** to choose the Administrator who will receive mobile notifications. 8. **Save the Configuration:** Click **Save** to apply the changes.