ObsidianDocumentation Sign in

Users & roles

Manage › Users lists everyone who can sign in or receive a quarantine: synced mailbox users, organization administrators and MSP staff.

Roles

User
Their own quarantine, recent mail, personal lists and account security. No admin console.
Organization administrator
The admin console for their own organization only. Cannot see Settings, System health or API tokens, or other organizations.
MSP administrator
Everything. Only MSP administrators can create other MSP administrators.

Finding users

Search by address or name; filter by organization (MSP administrators) and role. The list shows VIP and disabled badges, alias counts, sign-in method (local, m365, google, ldap, "+ MFA") and last sign-in.

Add user

Email
Sign-in name and primary address.
Name
Display name (matters for VIP protection).
Organization
(MSP administrators.) "none - MSP staff" for your own team; required for users and organization administrators.
Role
See above.
Password
Optional, 12+ characters. Leave blank for people who sign in with Microsoft / Google, their Windows password (Exchange), or email links.

Mailbox users normally arrive through user sync rather than being added by hand.

Editing a user

Display name
Shown in the console and used for impersonation checks.
Role, Organization
You cannot change your own role.
Aliases
Other addresses delivered to this mailbox (comma separated). Mail to an alias shows in this user's quarantine and counts for recipient checks. Sync fills these from the directory.
Active
Unticked users cannot sign in and are skipped by digests. (You cannot deactivate yourself.)
VIP
Protects the display name: external mail using this person's name gets VIP_DISPLAY_NAME (+6) and is always shown to the AI. Mark executives, finance and HR approvers.
Send quarantine digests
Whether this person receives digests (users can change this themselves too).
Set new password
Resets the password; the user's existing sessions end.
Reset two-factor
Removes their authenticator so they can enrol again (lost phone).

Saving also clears any lockout from failed sign-ins. Every change is written to the audit log.

Personal allow & block entries

The right-hand card lists the user's own list entries; Remove deletes one.