Enrolled Users Report :
The Enrolled Users report provides you with the list of users who have enrolled themselves in ADSelfService Plus. Enrollment provides users with access to the password reset and account unlock portal. It also protects the user accounts through the MFA methods the users have enrolled for. The report displays the users' mail addresses, users' mobile numbers, OU, the time of enrollment and the last time the enrollment was modified of the users.
Report filtering and generation:
- Specify the domain using the Select Domain option.
- Specify OUs (if necessary) using the Add OUs option.
- Enrollment status: Use the Enroll Status drop-down to filter the entries based on whether the users are Enrolled or Partially Enrolled. Enrollment status is considered based on the fulfillment of the below conditions. If all these conditions are satisfied, then the user's enrollment is treated as Enrolled If not, the user is considered Partially Enrolled.
- Condition 1: The user has enrolled for all mandatory authenticators.
- Condition 2: The user has enrolled for the required number of authenticators set by administrators.
- Condition 3: If security question is configured as the authenticator, the user has enrolled with all the mandatory questions and the correct number of questions.
- Enrollment type: Filter the results based on MFA methods using the Enrollment Type drop-down.
- Click Generate to generate the report.
Sorting:
Click any of the columns to view the report's entries in ascending or descending order.
Searching:
- Click the search icon [
] to search for specific data in the columns displayed.
- Search for a particular user using SAM Account Name, Display Name, E-mail Address, Mobile Number, and OU Name.
- Search will take place with the criteria contains. For example, if the User Name field is searched with the keyword jack, all usernames that contain jack will be displayed.
Export and More:
- The Export As option in the right corner of the page helps export the report in various formats like CSV, CSVDE, HTML, PDF, and XLS.
- The More option in the right corner of the page lists the Printable View, Send Mail, and Export Settings options.
- The Printable View option can be used to preview the report.
- The Send Mail option can be used to email the report to the desired email addresses.
- The Export Settings option allows users to customize the description and logo that will be used in the exported report. Also, admins can opt to keep the logo on every page of the exported report.
Disenrolling a user
Disenrollment of a user involves completely removing their enrollment information from ADSelfService Plus. Once a user is disenrolled, they will not be able to perform self-service actions; the user must be enrolled again to perform the actions. Disenrollment of users can be done two ways:
- Manual: Choose users whom you want to disenroll by clicking the available check box in the first column of each row and then selecting the Disenroll button next to the search button.
- CSV: Click the Bulk Disenroll button in the right corner of the report header, near the navigation buttons. Upload a CSV file that contains a list of the users’ SAM Account Name, Mobile Number, or Mail ID to disenroll them.
Generating backup codes
Admins can generate a backup code for an enrolled user when the user's MFA device is not reachable. The user can use each backup code only once. To generate a backup code for a specific enrolled user:
- Go to the Enroll Status column and hover over the enrollment status entry of the specific user. The MFA Backup Code option will appear; select this option.
- The Generate MFA Backup Code section appears. Here the following details are displayed:
- SAM Account Name: The samAccountName value for the user.
- Domain Name: The domain the user belongs to.
- Generated time: The date and time of the backup code generation.
- A table displays the newly generated single-use backup code.
- Use the Expire (Mins) field to specify the number of minutes after which the code will expire.
- Click the copy icon next to the backup code to copy it. The code should be sent or conveyed to the user to let them verify their identity without MFA.
- Click Close.
Note:If more than one technician creates backup codes for the same user, then the most recently generated code becomes valid, and this code can only be used once. If the user had generated a backup code themselves, then that will also remain valid until it's used.