Authentication Tokens (Credentials) (authenticationTokens)
Description
List of authentication tokens that can be managed in the Adminapp.
Attributes
Assignable plugins
Users Are Editable (editable)
Description
If this property is enabled, user data (profile items, roles and validity) are editable, new users can be inserted, and users can be deleted.
Attributes
Default value
true
Available User Roles (availableUserRoles)
Description
Set of roles assignable to users.
Translations for the roles displayed in the Adminapp user management UI can be defined using the Adminapp translation keys roles.user.labels.[rolename].
This setting can be overwritten by "Admin Role Specific Settings".
Attributes
User Activities Message Filters (UI) (activitiesMessageFilters)
Description
Predefined message filters for the search in the user's 'Activities' tab. The filters are offered in a dropdown on the message filter input. This allows administrators to quickly filter for user events such as password changes or logins to a specific application.
Attributes
Assignable plugins
Show User Valid Section (showUserValidSection)
Description
If this property is enabled, a section with the user valid status, valid-from and valid-to dates (if information is available) is displayed. On the user edit page, the valid-from and valid-to dates can be edited.
Attributes
Default value
false
User Locked Section (userLockedSection)
Description
Defines the visibility of the user-locked section on the user details page:
- SHOW: show all attributes (the default)
- RESTRICTED: show some attributes suitable for users in Active Directory (no lock reason or date; unlock button but no lock button)
- HIDE: do not show the user locked section
Attributes
Default value
SHOW
Language Context Key (languageContextKey)
Description
Defines the name of the context data property with the users correspondence language. It is used when rendering letters. This property is optional (if it is not set, no language information is available for the renderer plugins.)
Attributes
Suggested values
language
Max Users To List (maxUsersToList)
Description
The maximum number of users to list per page.
Attributes
Default value
50
Username Search Field (usernameSearchField)
Description
Defines the context-data field that the user search uses instead of the actual 'username'. It has the following effects:
- The user search never searches in the default 'username' field, but in the configured field instead.
- This applies also if the 'Only search username' checkbox is selected.
- The 'username' column in the search result list displays the value of this field.
- The title of the user detail pages uses the value of this field.
Only fields that are set on all users (e.g. login alias) should be used. Users without a value in this field might not appear in search results or will be listed with empty usernames.
Attributes
Assignable plugins
Default Sort Column (defaultSortColumn)
Description
Defines the column in the user list to sort by default. Use one of the preconfigured columns "username", "locked", or "last-successful-login", use "realm" to sort by a configured realm column, or use the property name of a context data column (e.g. "givenname"). If left empty, the default sort order is unspecified.
Attributes
Suggested values
username, locked, last-successful-login, realm
Sort Ascending By Default (sortAscendingByDefault)
Description
If enabled (and a "Default Sort Column" is set), the default user sort is ascending, otherwise descending.
Attributes
Default value
true
Columns In User List (columnsInUserList)
Description
The additional columns to show in the user list page.
This can be used to show context data or other information from a user, for example the first- or lastname.
The configured columns are inserted after the username column.
Attributes
Assignable plugins
User Profile Items For Search (userSearchProfileItems)
Description
The items referring to "Columns In User List" that can be included in the search on the user list page. If no properties are configured, the search will not filter on context data items. If the referred item is not configured in the "Columns In User List", it will be ignored. The configured properties are searchable in through the search functionality.
Note: Currently only string and list items are supported by the search. All other items will be ignored.
Attributes
Assignable plugins
Rows On User Detail Page (rowsOnUserDetailPage)
Description
The property names and labels of context data to be displayed on the user detail page.
The data is taken from the context data container of the selected user. The configuration of the used user persister must include the context data properties referenced here.
Note: The username is always displayed and can therefore not be configured here. Whether it is editable can be configured in the "Access Control" configuration in the "Admin Tool" root node.
Attributes
Assignable plugins
User Data Source (userDataSource)
Description
Defines how to load and store users in the Adminapp.
This setting can be overwritten by "Admin Role Specific Settings".
Attributes
Assignable plugins
Admin Role Specific Settings (adminRoleSpecificSettings)
Description
This list of admin role specific settings allows to overwrite certain settings for administrators with a specific set of roles. More details on what behaviour can be overwritten can be found within the plugin itself. The first Admin Role Specific Setting that matches the administrator's roles based on the "Role Specific Settings Selection" is used.
Attributes
Assignable plugins
Role Specific Settings Selection (roleSpecificSettingsSelection)
Description
The strategy to select the role specific settings for an administrator. The first Admin Role Specific Settings that match the administrator's roles are used. If there is no matching entry, no role-specific settings are used.
Attributes
Assignable plugins
Account Link Management Config (accountLinkManagementConfig)
Description
Configures the account link management. If account linking is configured and a user has account links, the account links tab, including the users account links, is displayed on the user detail page.
Attributes
License-Tags
OAuthAccountLinking
Assignable plugins
Locking Settings (lockingSettings)
Description
Configures the behavior of user locking.
Attributes
Assignable plugins
Show Migration Section (showMigrationSection)
Description
If enabled, the credential migration section is displayed on the user details page. This section contains a choice of authentication methods to be assigned to the user after migration.
Attributes
License-Tags
TokenSelfService
Default value
false
Enable Multiple Next Auth Methods (enableMultipleNextAuthMethods)
Description
If enabled, multiple methods can be selected to which the user can migrate. On the migration hint page the users will be given a choice to which methods they would like to migrate. This is only functional if "Show Migration Section" above is also activated. Also remember to enable support for multiple next authentication methods on the migration hint page settings for the login app.
Attributes
License-Tags
TokenSelfService
Default value
false
User Management Extensions (userManagementExtensions)
Description
User Management Extensions are added as a tab in the User Management of the Adminapp.
For someone to see the User Management Extension, they need to have the corresponding access rights. This has to be set in the Adminapp Access Control.
Please consult the official Airlock IAM documentation for more information
Attributes
Assignable plugins
Additional Auth Method Properties (additionalAuthMethodProperties)
Description
This setting is used if more than one active authentication method must be managed in the Adminapp. It defines a list of user context properties. The properties are used to store the additional active authentication methods (and to select the corresponding translation for the label on the user details page).
Make sure that the corresponding context properties are supported (i.e. configured in) by the configured user persister.
Attributes
Allow Bulk Changes (allowBulkChanges)
Description
If enabled, the next authentication method and the migration date may be changed for multiple users simultaneously (bulk change).
Whether a property is available for bulk changes or not depends on the corresponding settings of the user details page (e.g. if the credential migration section is enabled on the user details page, it is also visible on the bulk changes page).
The bulk change page is accessible from the user list page.
Attributes
Default value
false
User Identity Generator (userIdentityGenerator)
Description
If configured, this plugin is used to generate the ID (username) of new users. The "Create new user" dialogue in the Adminapp will not contain a username input field. REST requests to create a new user (POST /<adminapp-uri>/rest/users) will use this generator to create a user ID (instead of the default UUID generator)
Attributes
Assignable plugins
Username Prefill (usernamePrefill)
Description
If configured, the username field on the user create and username change dialog is prefilled with the provided value. This feature can be used to suggest administrators on possible usernames or to prefill a common username prefix.
Attributes
Assignable plugins
Username Validator (usernameValidator)
Description
If configured, validates the username of new users before they are created. If the username is invalid, creation of this user fails with a corresponding validation error.
Be aware that independent of this validator, IAM enforces two default username validations on provided usernames:
- Uniqueness Validation - the provided username must not already exist on the database
- Minimum Length Validation - the provided username must be at least 2 characters long
Note that these validators (configured and default) are only applied for provided usernames and do not validate generated ones, i.e. when configuring a User Identity Generator.
Attributes
Assignable plugins
Group Settings (groupSettings)
Description
Some settings may be defined depending on a user's group membership (e.g. if the user is readable or not).
This list defines group-specific settings:
- If the group's condition is met by the user, the corresponding settings are used for this user.
- It is processed in order of definition, i.e. the first matched group condition determines the settings used.
- If no group condition is met, the global user settings are used (= the ones just above).
Attributes
Assignable plugins
Case-Sensitive Search As Default (caseSensitiveSearchAsDefault)
Description
Sets the default strategy for searching users. If enabled, searching is case-sensitive. Otherwise, searching is case-insensitive. The search strategy can always be altered by the corresponding checkbox on the user search page.
Attributes
Default value
true
Only Search Words As Default (onlySearchWordsAsDefault)
Description
Sets the default strategy for searching users. If enabled, the search term must exactly match the username or an attribute to be found (equals-matching). Otherwise, the search term must be contained within the data (contains-matching). The search strategy can always be altered by the corresponding checkbox on the user search page.
Attributes
Default value
false
Search In Username As Default (searchInUsernameAsDefault)
Description
Sets the default strategy for searching users by their username. If enabled, the default search matches the term against the username (or the field configured as "Username Search Field", respectively). Otherwise, search is only performed on the configured "User Profile Items For Search". The search strategy can always be altered by the corresponding checkbox on the user search page.
Attributes
Default value
true
Advanced Search Filters (advancedSearchFilters)
Description
Advanced search filters allow for extended search options. Please note that some filters can only be applied if a User Store with the required capability is configured.
Attributes
Assignable plugins
Automatically Perform Last Search (automaticallyPerformLastSearch)
Description
When enabled, the last user search is automatically performed again when navigating back to the user search page. When disabled, the last search term is still retained but the search must be triggered manually by the administrator. Disabling can be helpful in cases where searches can take a lot of time.
Attributes
Default value
true
Export (export)
Description
Configures the download of user data. If the download is not configured, it is not available in the Adminapp.
Attributes
Assignable plugins
Remember-Me Management Enabled (rememberMeManagementEnabled)
Description
If configured, the administrator will be able to delete all persisted Remember-Me tokens for a user on the user overview page.
Attributes
Default value
false
Remember-Me Settings (rememberMeSettings)
Description
If configured, the administrator will be able to delete all persisted Remember-Me tokens for a user on the user overview page.
Attributes
Assignable plugins
OAuth 2.0 Authorization Servers (oauth2AuthorizationServers)
Description
List of authorization servers where the users have OAuth 2.0 Tokens. This can for example be used to delete tokens on password changes by administrators.
Attributes
Assignable plugins
Admin Cannot Delete User With Same Name (adminCannotDeleteUserWithSameName)
Description
If enabled, administrators cannot delete users who have the same username as themselves. This applies regardless of where the admin or user are stored and prevents accidental self-deletion.
This can be useful if admin users are stored in the regular user repository.
Attributes
Default value
false