Docs/Users & sign-in/Users and groups
DartRelay 2.1 documentation
Users & sign-in

Users and groups

This page explains who can sign in to the portal, how to create and manage DartRelay's own portal accounts, and how to bundle people into user groups so you can give them access in one step.

The three kinds of account

DartRelay can accept people from three different places. You can use one, two or all three at once, and you choose which are switched on in Authentication → Authentication Methods.

Sign-in sourceWhere the account livesTypical use
Portal UsersInside DartRelay itself. You create the account, set the password and manage it in the console.Contractors, customers, small offices without a domain, or a guest account for public access.
Domain UsersIn Active Directory. DartRelay checks the password with your domain controllers and reads the person's groups.Staff who already have a Windows domain account. This is the most common choice in a company with a domain.
Windows UsersIn the local account list of the Windows machine that runs DartRelay.A DartRelay server that is not joined to a domain, or a handful of local accounts kept on that machine on purpose.

Portal Users is switched on by default. Domain Users and Windows Users are off until you switch them on.

Note

Switching a source off really does stop it. If you turn Portal Users off, portal accounts can no longer sign in to the portal at all. Administrators are not affected: the console has its own sign-in, so you cannot lock yourself out of the console this way.

Which account is tried first

When somebody types a plain username with no domain in front of it, DartRelay checks in this order:

  1. DartRelay's own portal accounts (if Portal Users is on).
  2. Active Directory (if Domain Users is on).
  3. The local Windows accounts on the DartRelay server (if Windows Users is on).

A name typed with a domain, such as CORP\alice or alice@corp.example.com, goes straight to that domain and nowhere else. Active Directory and multiple domains explains this routing in detail.

The portal-first order is deliberate and cannot be changed. If DartRelay asked the domain first, every portal-account sign-in would send the portal password to your domain controller as a guess against any domain account with the same name, and a person who has both kinds of account could end up locking their real Windows account out.

The same name in two places

A person can have a portal account and a domain account with the same username. Either password works: if the portal password does not match, DartRelay goes on to ask the domain. Remember that the two are separate accounts with separate access, so the resources they see depend on which password they used.

Portal accounts

Portal accounts are managed under Authentication → Users. The list shows ordinary portal users only; administrators are kept separately under System → Admin Users (see Administrator roles and permissions).

Create a portal account

  1. Open the Users page. In the console, go to Authentication → Users.
  2. Add a user. Fill in the username, the password and the person's email address.
  3. Decide about the first password. When an administrator creates an account or sets somebody's password, the account is marked so that the person must choose a new password the first time they sign in. Leave this on unless you have a reason not to.
  4. Choose groups, if you use them. The Group Membership section lets you place the person in one or more user groups straight away.
  5. Save. The person can now sign in to the portal. They see only the resources that have been granted to them, to one of their groups, or to everyone.
FieldWhat it doesDefault
UsernameWhat the person types to sign in. An email address can be used as a username.—
PasswordThe portal password. It must meet the rules set under Authentication → Security; see Password policy and self-service reset.—
EmailUsed for emailed one-time codes, the welcome message and the forgot-password link. An account with no email cannot use self-service password reset.—
Must change passwordForces a new password at the next sign-in. Cleared automatically once the person has changed it.On when an administrator creates the account or sets its password
ActiveAn inactive account cannot sign in. Use this to suspend somebody without deleting them.On
Group MembershipThe user groups this person belongs to. Inactive groups are shown dimmed.None
AdministratorTurns the account into a console administrator. Only an administrator with Full permission on Admin Users can change this.Off
Tip

If the people you publish to all have domain accounts, you do not need portal accounts for them at all. Directory users never appear in the Users list: they sign in with their domain account and are given access through their own name or their Active Directory groups.

User groups

A user group bundles portal accounts together so that you can grant a desktop, an application group or a web application to many people at once, and change who has it by changing the group rather than every resource.

User groups hold portal accounts only. To grant access to domain users as a group, use their Active Directory group directly in the access picker; you do not need to recreate it in DartRelay. See Giving people access to resources.

Create a user group

  1. Open the User Groups page. Go to Authentication → User Groups. The list shows each group's name, description, member count, how many resources it has been granted, and whether it is active. Use the filter box to find a group quickly.
  2. Add a group. Give it a name (it must be unique, up to 128 characters) and, optionally, a description that tells other administrators what it is for.
  3. Tick the members. The member grid lists every portal account. Use the filter box, or Select all and Clear, to pick people quickly.
  4. Save. The group opens in its edit page, ready for more changes.
FieldWhat it doesDefault
NameShown in the access picker as a Portal Group. Must be unique.—
DescriptionA note for administrators.Empty
ActiveAn inactive group grants nothing: its members lose every resource they had only through this group, without you removing the group from each resource.On
MembersThe portal accounts in the group.None

Change membership from either side

You can add people to a group from the group's own page, or open a user under Authentication → Users and tick groups in their Group Membership section. Both change the same thing.

See where a group is used

Each group's edit page has a Where this group is used table listing every desktop, application group and web application it has been granted, with a link to each. Check this before you delete or deactivate a group.

Important

A user group can also be named on a portal address under Appearance → Tenancy & Branding, to decide who may sign in there. That use does not appear in the Where this group is used table. If you delete a group that was the only one allowed on an address, that address admits nobody until you choose another group. See Tenancy & Branding.

Suspending a whole group

Untick Active on a group to withdraw everything it grants in one step. Members keep any access they have through other groups, through their own name, or through resources open to everyone. Tick it again and the access returns.

Example: a firm with staff and outside accountants

A company has 40 staff in Active Directory and six external accountants who have no domain account.

If something goes wrong

ProblemWhat to check
A portal account cannot sign in at all.Check that Portal Users is on in Authentication → Authentication Methods, that the account is active, and that the address they are using admits them (see Tenancy & Branding).
A person signs in but sees "No resources have been assigned to your account yet".Nothing has been granted to them, their groups, or everyone. Check that the group they rely on is active. See access troubleshooting.
A user has a domain account and a portal account, and sees different resources on different days.They are signing in with different passwords, so as two different accounts. Decide which one they should use and remove the other.
Somebody is asked to change their password every time.The new password probably does not meet the password rules. The change page says which rule failed.
A user group does not appear in the access picker.The picker only lists portal groups when Portal Users is on. Inactive groups still appear, but grant nothing.
Still stuck? Email support@dartinnovations.com with what you were doing, what you expected and what you saw. A screenshot helps.