---
metadata:
  - name: generator
    content: Diplodoc Platform v5.63.0
alternate:
  - en/security/manage-users
  - ru/security/manage-users
  - href: en/security/manage-users.md
    type: text/markdown
    title: Markdown version
csp:
  - script-src:
      - https://mc.yandex.ru
    img-src:
      - https://mc.yandex.ru
    connect-src:
      - https://mc.yandex.ru
      - wss://mc.yandex.ru
    child-src:
      - 'blob:'
      - https://mc.yandex.ru
    frame-src:
      - 'blob:'
      - https://mc.yandex.ru
    frame-ancestors:
      - 'blob:'
      - https://mc.yandex.ru
canonical: en/security/manage-users.html
title: How to manage users in DataLens On-premises
description: Follow this guide to manage users in DataLens.
vcsPath: en/security/manage-users.md
---

# User management in DataLens On-premises

In DataLens, user management is performed by the administrator, i.e., user with the `Admin` (`datalens.admin`) [role](./roles.md#datalens-admin). For other users to be able to log in to DataLens, the administrator has to create accounts for them. There are two types of accounts:

* Local. These user accounts are created and stored only in DataLens. [Learn more about creating local accounts.](#add-user)
* From an identity provider (IdP) service, e.g., [LDAP](../concepts/auth-ldap.md), [OIDC](../concepts/auth-oidc.md), Active Directory, OpenId, Keycloak, Zitadel.


## User accounts {#account}

A user account consists of:

* User profile: First name, last name, login, email, ID, IdP.
* Password.
* [Role](./roles.md#service-roles).

The administrator can view the list of all users and their accounts. To do this:

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab to see the list of all users.
1. To view a user account, click the line with the login.

## Creating a user account {#add-user}

There are two ways to create a user account in DataLens:

* The user signs up to DataLens by following [this guide](user-account.md#sign-up). In which case, the user gets the minimum [role](./roles.md#datalens-visitor), `Visitor` (`datalens.visitor`). The administrator [edits the new account](#edit-user).
* The administrator creates an account for the user and provides the login and temporary password. The users changes the password on first sign-in according to [this guide](./user-account.md#edit-password).

To create a user account:

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab and click <!-- diplodoc:svg ![image](../_assets/console-icons/plus.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M8 1.75a.75.75 0 0 1 .75.75v4.75h4.75a.75.75 0 0 1 0 1.5H8.75v4.75a.75.75 0 0 1-1.5 0V8.75H2.5a.75.75 0 0 1 0-1.5h4.75V2.5A.75.75 0 0 1 8 1.75" clip-rule="evenodd"/></svg> **Add user**.
1. Complete the user profile:

   * **Login**. Enter the user’s login used to sign in and identify the account. Choose the login as per these requirements:

     * From 3 to 200 characters long.
     * Starts with an uppercase or lowercase Latin letter.
     * Other characters are uppercase or lowercase Latin letters, numbers, `_`, or `-`.
     * Ends with an uppercase or lowercase Latin letter or a number.
     * You can also use an email address as the login.

   * Optionally, specify the user’s **First name**.
   * Optionally, specify the user’s **Last name**.
   * Optionally, specify the user’s **Email**.
   * **Role**. Select a [role](./roles.md#service-roles) for the user. You can change the role when editing the user profile.
   * **Password**. Enter a password the user will sign in with. Choose the password as per these requirements:

     * From 8 to 200 characters long.
     * Contains at least one uppercase Latin letter and one lowercase Latin letter.
     * Contains at least one number.
     * Contains at least one of these characters: `!`, `@`, `#`, `$`, `%`, `^`, `&`, `*`, `-`, or `_`.
     * Other characters: any.

1. Click **Add**.

Communicate the login and password to the user with an instruction to change the password on first sign-in as per [this guide](./user-account.md#edit-password).

## Editing a user account {#edit-user}

The administrator can [edit](#admin-edit-user) any user account, including their own one. Accounting editing includes:

* [Editing the profile](#edit-profile)
* [Changing the password](#change-password)
* [Assigning a role](#assign-role)
* [Deleting the account from the system](#delete-user)

### Editing a user profile {#edit-profile}

To change the user profile information:

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab.
1. To the right of the user's name, click <!-- diplodoc:svg ![image](../_assets/console-icons/ellipsis.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M3 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3M9.5 8a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m5 0a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0" clip-rule="evenodd"/></svg> → **Edit profile**.
1. Edit the user’s first name, last name, or email address. Click **Save**.

### Changing the password {#change-password}

If the user has forgotten their password, you can reset it and set a temporary one for the user to be able to log in. To change the user's password:

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab.
1. To the right of the user's name, click <!-- diplodoc:svg ![image](../_assets/console-icons/ellipsis.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M3 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3M9.5 8a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m5 0a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0" clip-rule="evenodd"/></svg> → **Change password**.
1. Enter or generate a temporary password and click **Save**. Communicate this password to the user and tell them to change it on first sign-in as per [this guide](./user-account.md#edit-password).

### Assigning a role {#assign-role}

To change the [user’s role in the service](./roles.md#service-roles):

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab.
1. To the right of the user's name, click <!-- diplodoc:svg ![image](../_assets/console-icons/ellipsis.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M3 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3M9.5 8a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m5 0a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0" clip-rule="evenodd"/></svg> → **Assign a role**.
1. Select a role from the drop-down list and click **Save**.


### Adding a user to a group {#add-to-group}

To add a user to a [group](./manage-user-groups.md):

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab.
1. Click the user row to open their personal account.
1. Under **Groups**, click **Add to group**.
1. Select a group to add the user to.
1. Optionally, to add a user to another group, click <!-- diplodoc:svg ![image](../_assets/console-icons/plus.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M8 1.75a.75.75 0 0 1 .75.75v4.75h4.75a.75.75 0 0 1 0 1.5H8.75v4.75a.75.75 0 0 1-1.5 0V8.75H2.5a.75.75 0 0 1 0-1.5h4.75V2.5A.75.75 0 0 1 8 1.75" clip-rule="evenodd"/></svg> **Select group**.
1. Click **Save**.

You can also [add or remove a user from a group](#change-member-list) on the group page.


### Deleting a user {#delete-user}

{% note warning %}

The administrator cannot delete their own account.

{% endnote %}

To delete a user:

1. In the navigation panel on the left, click <!-- diplodoc:svg ![image](../_assets/console-icons/sliders.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M7.5 5a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m1.405.75a3.001 3.001 0 0 1-5.81 0H1.747a.75.75 0 0 1 0-1.5h1.348a3.001 3.001 0 0 1 5.81 0h5.345a.75.75 0 0 1 0 1.5zm-7.158 4.5h5.345a3.001 3.001 0 0 1 5.811 0h1.347a.75.75 0 1 1 0 1.5h-1.347a3.001 3.001 0 0 1-5.81 0H1.746a.75.75 0 0 1 0-1.5m8.25-.75a1.5 1.5 0 1 0 0 3 1.5 1.5 0 0 0 0-3" clip-rule="evenodd"/></svg> **Service settings** to open settings.
1. Go to the **Users** tab.
1. To the right of the user's name, click <!-- diplodoc:svg ![image](../_assets/console-icons/ellipsis.svg) --><svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="none" viewBox="0 0 16 16"><path fill="currentColor" fill-rule="evenodd" d="M3 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3M9.5 8a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0m5 0a1.5 1.5 0 1 1-3 0 1.5 1.5 0 0 1 3 0" clip-rule="evenodd"/></svg> → **Delete user**.
1. To confirm deletion, click **Delete user**.
