> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/user-management.md).

# User management

To access Cortex XSOAR, users must either be added to Cortex XSOAR locally or via SSO. When logging into Cortex XSOAR users must have an assigned role. If no role is assigned either directly or via a user group, users can log in but can't access the tenant.

On the **Users** page, you can view user information, such as user type, role, and user groups.

#### User information

| Name            | Description                                                                                                                                                                                                                                                                                                                                                                                       |
| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User Type       | <p>Indicates whether the user was <strong>Local</strong> (added in Cortex XSOAR), <strong>SSO</strong> (single sign-on) using your organization’s IdP, or both <strong>Local/SSO</strong>.</p><p>For information about enabling SSO in Cortex XSOAR, see <a href="/pages/zqduRxcmVqXRwbR4gLB0">Authenticate users using SSO</a>.</p>                                                              |
| Direct Role     | Name of the role assigned to the user (not inherited from elsewhere, such as a User Group).                                                                                                                                                                                                                                                                                                       |
| Groups          | <p>Lists the user groups to which a user belongs.</p><p>Any group imported from Active Directory has the letters <strong>AD</strong> added beside the group name.</p><p>If a user is assigned to multiple user groups, which are mapped to different roles, or if the user is assigned to nested user groups, the user has the highest level of privileges based on the combination of roles.</p> |
| Group Roles     | Lists the different group roles based on the groups to which the user belongs. When you hover over the group role, the group associated with this role is displayed.                                                                                                                                                                                                                              |
| Last Login Time | Last date and time the user accessed Cortex XSOAR.                                                                                                                                                                                                                                                                                                                                                |
| Status          | Displays whether the user is **Active** or **Inactive**                                                                                                                                                                                                                                                                                                                                           |
| Phone number    | Displays the user's phone number. Including the user's phone number enables playbooks and scripts to trigger direct analyst communication by phone.                                                                                                                                                                                                                                               |
| Tenants         | <p>Displays the main or child tenant the user is allowed to access.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Users created on child tenants can't assume a user group or a role propagated from the main tenant.</p></div>                                                                                            |

<details>

<summary>Create users</summary>

To add users locally (not SSO), you can either send an invitation to users by adding their details manually or by uploading a CSV file with multiple users. See [Create users in Cortex XSOAR](/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md).

</details>

<details>

<summary>Add/update user roles</summary>

You can update user roles for one or multiple users. You can add/update the following user roles:

* **Pre-Defined roles**: Instance Administrator and Account Admin.
* **Custom roles**: Includes out-of-the-box roles and roles.

{% hint style="info" %}

### Note

To update the permissions attributable to each role, you need to change them in the **Roles** tab.
{% endhint %}

1. Go to **Settings & Info** → **Settings** → **Access Management** → **Users**, and do one of the following:
   * To edit one user, right-click the user's name and select **Edit Users Permissions**.
   * To edit multiple users, select multiple users, right-click, and select **Edit Users Permissions**.
2. In the **Role** field, select one of the pre-defined or custom roles.
3. Add User Groups if required.
4. Save the user role.

{% hint style="info" %}

### Note

If no role is assigned either directly or via a user group, users do not have view or edit permissions in Cortex XSOAR.

The **Show Accumulated Permissions** field shows the roles and user groups assigned to the user. You can also select the specific roles assigned to the user, which enables you to compare available permissions based on the roles selected. This can help you understand how the role permissions for a particular user are built. For example, if you need to isolate a specific component, the permissions are provided by a particular role or user group.
{% endhint %}

</details>

<details>

<summary>Remove a user role</summary>

If a user has a role in the tenant (besides Account Admin), you can remove their user permission to access the tenant. If no direct or user group role has been assigned, the user has no permission to view or edit data in Cortex XSOAR.

1. In the **Users** tab, right-click the user's name and select **Remove User Role**.
2. Confirm that you want to **Remove** the user role.

</details>

<details>

<summary>Unlock users</summary>

If the user's account has been locked, for example, due to too many login attempts, you can unlock the user.

{% hint style="info" %}

### Note

The user has up to 10 attempts to log in before being locked. In any event, the user will be unlocked after 15 minutes.
{% endhint %}

1. Go to Settings & Info → Settings → Access Management → **Users** and select the user.
2. Right-click the user and then select **Unlock**.

   The user's status changes to **Active**.

</details>

<details>

<summary>Deactivate users</summary>

Users should be deactivated to temporarily remove user access to Cortex XSOAR. All user information is maintained for deactivated users. Users should be permanently removed if they no longer need access to Cortex XSOAR.

{% hint style="info" %}

### Note

When you remove a role, the role associated with the API keys is deleted. When a user is deactivated, the API keys that the user created are not revoked.

* If more than one role was associated with the API key, a yellow warning symbol appears next to the API key in the API key table. When you hover over the symbol, a message indicates that some of the roles associated with the API key have been deleted.
* If all roles associated with the API key are removed, a red warning symbol appears next to the API key in the API key table. When you hover over that symbol, a message indicates that the key is no longer usable because it does not have a role associated with it. The API key is still visible in the API table but it cannot be assigned.
  {% endhint %}

If the user is assigned to incidents or tasks or is the owner of a dashboard, these assignments do not automatically change when the user is removed or deactivated. We recommend changing incident and task assignments manually before removing or deactivating users.

Any reports the user has created remain available. Reports are not owned by specific users and can be edited or deleted by other users.

{% hint style="info" %}

### Note

When you remove a role, the role associated with the API keys is deleted. When a user is deactivated, the API keys that the user created are not revoked.
{% endhint %}

Before you begin:

* Reassign open incidents to another user.

  Go to the **Incidents** page and search for **`-status:closed owner:`*****`user_name`*** to find any incidents the user is assigned and reassign.
* Reassign tasks to another user.

  Go to the **Incidents** page and search for **`-status:closed investigation.users:`*****`user_name`*** and reassign.

  When a user is assigned a task in an incident, the user is added to the incident. This search finds all incidents where the user is a participant.

How to deactivate users

1. Go to Settings & Info → Settings → Access Management → **Users** and select the user.
2. Right-click the user and then select **Deactivate User** and then **Deactivate** to confirm.

</details>

<details>

<summary>Delete users</summary>

In Cortex XSOAR, you can permanently remove a user, or temporarily disable a user. Users should be permanently removed if they no longer need access to the system.

{% hint style="info" %}

### Note

You cannot deactivate or delete a user that has an Account Admin role.
{% endhint %}

When you delete users, all their personal information is deleted, including email addresses, usernames, phone numbers, and first and last names.

Before you begin:

* Reassign open incidents to another user.

  Go to the **Incidents** page and search for **`-status:closed owner:`*****`user_name`*** to find any incidents the user is assigned and reassign.
* Reassign tasks to another user.

  Go to the **Incidents** page and search for **`-status:closed investigation.users:`*****`user_name`*** and reassign.

  When a user is assigned a task in an incident, the user is added to the incident. This search finds all incidents where the user is a participant.

How to delete users

1. Go to Settings & Info → Settings → Access Management → **Users** and select the user.
2. Right-click the user and then select **Delete User** and then **Delete** to confirm.

{% hint style="info" %}

### Note

You can also delete a Single Sign-on (SSO) user. This option is only available when you’ve enabled [SSO](/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md) in Cortex XSOAR.
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/user-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
