User Management
Plan availability (2026-07-23): managing custom user-field definitions requires the Starter plan or higher. On the Free plan the field-definition page shows an upgrade screen; values already saved on user profiles remain visible in profiles, filters, and CSV exports.
Who this guide is for: Tenant administrators responsible for creating, managing, and deprovisioning users in the EmbayLMS platform.
Overview
EmbayLMS uses role-based access control. You can create users one at a time or import them from a CSV file, give them one or more roles, organize them into groups, and manage their access from first sign-in to offboarding and re-hire.
This guide covers:
- Creating users and importing them from CSV
- Built-in roles, custom roles and how roles combine
- Group Admins and groups (manual and dynamic)
- The manager relationship and account types
- Custom user fields
- SCIM provisioning and external users
- Deprovisioning and re-hiring
- Password, lockout, session and MFA settings
- Troubleshooting
Prerequisites
- Admin or Owner role on your EmbayLMS tenant (importing users from CSV needs the
user:importpermission, held by Admin and Owner) - A CSV file, if you are importing (see §9)
- Access to your identity provider, if you use SCIM provisioning (see SCIM Provisioning)
1 — Creating Users
1.1 Create an individual user
- Go to Users.
- Click Create User.
- Enter the user’s First name, Last name and Email address.
- Choose a Role (see §2).
- Optionally set an Initial password (see the field reference below).
- Set the Account type, the Manager and any custom fields your organization uses.
- Choose whether to Require password change on first login and whether to Send an invitation email.
- Click Create User.
Create User — field reference
| Field | Required | Description |
|---|---|---|
| First name | Yes | The user’s given name. |
| Last name | Yes | The user’s family name. |
| Email address | Yes | Must be unique within the tenant. Used to sign in. |
| Role | Yes | Learner (the default), Manager or Admin. The server only lets you assign a role at your own level or below. To give Instructor, Group admin, E-commerce admin or a custom role, create the user first, then use the Roles panel on their page (§3.2). |
| Account type | No | Internal (the default), Partner, Customer, Contractor or Volunteer. See §7b. |
| Manager | No | The person this user reports to. See §7b. |
| Custom fields | Depends | Every active custom field appears. A field marked Required must be filled in. See §8. |
| Initial password | No | A starting password, at least 8 characters. Leave it empty to have the user set their own password from an emailed link. The password is hashed and never shown again, so share it through a secure channel. |
| Require password change on first login | No | The user must choose a new password the first time they sign in. Only available when you set an initial password. |
| Send an invitation email | No (on by default) | Emails the user a welcome message. If you set a password, the email links to the sign-in page. If you did not, it carries a set-your-password link valid for 7 days. |
Which combination to use:
| Goal | Initial password | Require change | Send email |
|---|---|---|---|
| Let the user set their own password (classic invite) | empty | — | On |
| Hand a user a temporary password in person or through a secure channel | Set it | On (recommended) | Optional |
| Provision a shared or service account with a fixed password | Set it | Off | Off |
The password is never included in the email or in any log. When Require password change on first login is set, the user sees a full-screen prompt to choose a new password right after their first sign-in, and cannot reach the app until they do.
SSO tenants: If your tenant enforces SSO, users sign in through SSO rather than with a password. Leave the initial password empty. The invitation email still tells the user their account exists.
1.2 Import users from CSV
- Go to Users and click ⬆ Import CSV. The Import users page opens (Admin and Owner only,
user:import). - To start from a blank file with the right headers, click ⬇ Export template on the Users page (see §9).
- Prepare your file with these columns:
| Column | Required | Description |
|---|---|---|
external_id | One of external_id / email | Stable identifier from your HR or source system. Used first to match existing users. |
email | One of external_id / email | Unique in the tenant. Needed to create a new user. |
first_name | No | |
last_name | No | |
role | No | One built-in role: learner (default), instructor, manager, group_admin, ecommerce_admin, admin or owner. The legacy author is still accepted. Custom roles are not accepted here. |
locale | No | en (default) or fr-CA |
user_type | No | internal, partner, customer, contractor or volunteer. Empty keeps the current value on update and means internal on create. |
manager_external_id | No | The external_id of the user’s manager, or their email. Resolved after every row is created. |
group_names | No | Group names separated by a pipe, e.g. Sales|Ontario. Missing groups are created as manual groups. |
| custom field keys | No | One column per custom field (e.g. department). See §8. |
- Choose your file under CSV file and click Validate.
- The Validation preview lists each row with its errors. Nothing is saved yet.
- Fix the errors and upload again, or go ahead: rows with errors are skipped.
- Click the import button. It shows how many rows will be imported. The import runs in the background.
- When it finishes, you receive an email with the number of rows imported and the number that failed.
Limit: A single CSV file can be up to about 8 MB. For larger or continuous imports, split the file or use SCIM provisioning. Full column reference and troubleshooting: Data Import guide.
2 — Built-in Roles
EmbayLMS has seven built-in roles. Roles add up: a user with several roles has every permission of each (see §4). The Instructor, Manager and Group admin roles are scoped: they only reach the courses, people or groups they are tied to.
| Role | Scope | What it is for |
|---|---|---|
| Learner | Themselves | Browse the catalog, self-enroll where offered, attend training, follow their own progress and credentials. The default role. |
| Instructor | Assigned courses | Edit content, run in-person and virtual sessions, grade, and see analytics for the courses they are assigned to (course editor → Instructors tab). |
| Manager | Their report chain | See progress and analytics for everyone who reports to them, directly or indirectly (through the Manager field). Can also enroll their reports in courses and sessions. Cannot export reports or edit profiles. |
| Group admin | Assigned groups | Create and deactivate members of their groups, manage their enrollments and group membership, and see and export group reports. Cannot edit profile details such as custom fields, account type or manager. |
| E-commerce admin | Tenant | The whole E-commerce area: pricing, coupons, orders, refunds, revenue, storefront. Apart from the Owner, no other role gets e-commerce by default. |
| Admin | Tenant | Day-to-day administration of the whole tenant, including Roles and Permissions and importing users, but not Billing or the Settings area. |
| Owner | Tenant | Everything an Admin can do, plus the whole Settings area and Billing. Every tenant always has at least one Owner. |
The Author role is retired. Tenant-wide content authoring is Admin or Owner; course-scoped content editing is Instructor. Former authors were moved to a pre-built custom role named “Content Author” that keeps their previous permissions.
For the full permission matrix and the rules for assigning roles, see Roles and Permissions.
3 — Custom Roles
Custom roles let you define a precise set of permissions beyond the built-in roles. For example, a “Compliance Officer” role that can see compliance reports and nothing else.
3.1 Create a custom role
- Go to Settings → User Management → Roles and Permissions. The page is titled Custom Roles.
- Click New role, or Clone on any existing role to start from its permissions.
- Enter a Role name (e.g., “Compliance Officer”).
- Tick the permissions you need under Permission scopes. They are grouped by area, for example
user:view,course:edit,enrollment:create,report:view,report:export. You cannot grant a permission you do not hold yourself: those boxes are greyed out. - Click Save.
See Roles and Permissions for the full permission catalog.
3.2 Give a user more roles
- Open the user’s page (Users → click their name).
- Find the Roles panel.
- Tick the roles to add under Additional built-in roles and Custom roles.
- Click Save roles.
The user’s main role is changed separately, with Edit on their page.
3.3 Edit or delete a custom role
- To edit: on the Roles and Permissions page, click Edit on the role’s row. The editor opens on the same page.
- To delete: click Delete on the role’s row. A confirmation says how many people hold the role; click Delete again to confirm. The role is removed from every user who held it, and this cannot be undone.
Built-in roles are read-only: you can clone them, but not change or delete them.
4 — Role Cumulation
A user can hold more than one role at a time. Their permissions are the union of the permissions of every role they hold.
Example:
- A user holds both Instructor and Manager.
- They can do everything an Instructor can do (edit content, schedule sessions and grade in their assigned courses) and everything a Manager can do (follow the progress of their report chain).
Key rules:
- There is no conflict between roles: the most permissive access wins.
- Combining roles never widens a scope. Instructor rights stay limited to the assigned courses, and Group admin rights to the assigned groups.
- A user with Learner plus Admin has full day-to-day admin access, because Admin grants tenant-wide permissions. Settings and Billing remain Owner-only.
- Every role grant and removal is recorded in the audit log.
5 — Group Admin Role: Scoping and Assignment
A Group admin’s reach is tied to the groups they are assigned, not to the whole tenant. Two things are needed:
- The user must hold the Group admin role, as their main role or as an additional role (§3.2).
- They must be assigned to one or more groups, as below.
An assignment without the role has no effect.
5.1 Assign a Group admin to a group
From the groups list (Admin and Owner):
- Go to Groups. The Admins column shows who administers each group.
- Click Manage on the group’s row. A panel lists the Current admins, each with Remove.
- In Add a group admin, type at least two characters of a name or email and pick the person from the list (a click, or the arrow keys and Enter). People who already administer the group are not offered.
- Click Assign.
From the user’s page: open the user and use the Group Admin Assignments panel to add a group. Only Admins and Owners can make assignments.
Both paths do the same thing and are recorded in the audit log. A Group admin who opens the groups list sees the admins of their own groups only.
5.2 What Group admins can see and do
| Action | Allowed |
|---|---|
| See members of their assigned groups | Yes |
| Create and deactivate members of those groups | Yes |
| Enroll group members in courses | Yes |
| Export progress reports for their groups | Yes |
| Add or remove members of their groups | Yes |
| Edit a member’s profile details (custom fields, account type, manager) | No |
| See users outside their groups | No |
| Edit courses | No |
| Open the Settings area | No |
| See tenant-wide reports | No |
6 — Managing Groups
Groups organize users for reporting, enrollment and scoping. There are two types: Manual groups, whose members you add yourself or by CSV, and Dynamic groups, whose members follow rules and update automatically.
The Groups page lists every group with the columns Name, Description, Type (Manual or Dynamic), Members and Admins, and View and Edit on each row.
6.1 Create a manual group
- Go to Groups and click New Group.
- Enter a Name and, optionally, a Description.
- Leave the dynamic-group box unticked.
- Click New Group at the bottom of the form.
- On the group’s page, click Add Member. In People to add, search and pick each person (up to 50 at a time; people already in the group are not offered), then click the add button, which shows how many people you picked. If someone cannot be added, the dialog says how many were added and keeps the others selected so you can try again. To add many people at once, use a CSV file with the
group_namescolumn (§1.2) or the group-members import in the Data Import guide.
6.2 Create a dynamic group
A dynamic group includes every user who matches its rules.
- Go to Groups and click New Group.
- Enter a Name, then tick Dynamic group (auto-membership by rules) to show the rule builder.
- Build each condition:
- The attribute: Role, Language, Timezone, Email domain or User type.
- is or is not.
- The value, for example
enoracme.com.
- Click + Add condition for more, and choose whether members must match all conditions or any condition.
- Click New Group. Membership is filled from the rules and kept up to date as user details change.
6.3 Edit a group
On the Groups page, click Edit on a row:
- The Name and Description can be changed for every group.
- A dynamic group also shows its rules. Saving changed rules updates the membership right away: users who no longer match are removed, and newly matching users are added.
- The type cannot change after creation. To switch between manual and dynamic, create a new group.
6.4 Manage group membership
- Add people to a manual group: open the group and click Add Member.
- Remove someone: click Remove next to their name. People added by SCIM or by your identity provider are managed there and cannot be removed here.
- Dynamic groups: the member list is read-only. Change the user’s details or the group’s rules (§6.3) to change who is in it. Re-sync members refreshes the list on demand.
7 — Organizational Hierarchy
The organization chart in EmbayLMS is built from one thing: the Manager field on each user. There is no separate department structure.
| Feature | How the manager relationship is used |
|---|---|
| Team Roster (the manager’s team view) | Shows everyone in the manager’s report chain, directly or indirectly |
| Overdue escalation emails | Sent to the manager of a learner who is overdue |
| Report scoping | A Manager sees only their own chain |
Set a user’s manager as described in §7b, or with the manager_external_id CSV column.
Department is a custom text field that every tenant starts with. It is useful for filtering, reports and CSV exports, but it does not affect who reports to whom. Set it with Edit on the user’s page or with the department CSV column.
7b — Account type and manager
Two details live on every user beside their role. Both can be set on Create User and changed later with Edit on the user’s page. Changing them needs the user:update permission, which Admins and Owners have.
Account type
| Type | Use |
|---|---|
| Internal | An employee. The default. |
| Partner, Customer, Contractor, Volunteer | Everyone else, for filtering, targeting and reporting |
Account type is not a permission. It never changes what someone can do: the role does that. Use it to answer questions like “how many contractors completed the safety course”, to filter the Users list, and to report by audience.
In the Edit User panel, choosing an external type shows Account expires. From that date, sign-in is refused and any open session ends. Leave it empty for no expiry. The field is hidden for Internal, and switching back to Internal clears it.
Manager
Manager is the people-manager relationship, and it matters:
- it decides whose records a user with the Manager role can see (their report chain),
- it decides who receives the overdue-training digest for a learner, and
- it drives the manager’s team view.
Set it with the Manager search field: type at least two characters of a name or email, pick the person from the list (arrow keys and Enter work too), and they appear in a box with a Clear button to take them off. The person being edited is never offered as their own manager, and two things are refused when you save:
| Refused | Why |
|---|---|
| Making someone their own manager | They would be their own escalation target |
| Choosing someone who already reports to this user, at any depth | It would create a loop in the org chart |
Reading the chain
- The user’s page shows their Manager as a link, so you can walk up one click at a time.
- A manager’s own page lists their direct reports, each linked, with View the whole team → for everyone beneath them at any depth.
- The Users list has a Manager column. When you follow a team link, the list says which filter is on and offers Show all users.
Both changes are recorded in the audit log with the before and after values.
8 — Custom user fields
Add extra fields to every user, up to 50 per tenant. Two fields come built in and do not count toward the 50: Department (text) and Manager (the people-manager relationship in §7b).
Define a field
- Go to Users and click ⚙ Custom fields.
- The counter at the top shows how many of the 50 slots are used and how many remain.
- Click + New field, enter a label, choose a type (text, number, date, dropdown or user lookup) and, for a dropdown, its options.
- Choose how the field behaves. All three options are off by default:
| Option | Effect |
|---|---|
| Required | Must be filled in on Create User and in the Edit User panel. It is deliberately not enforced on CSV import or the API, so adding a required field never blocks a migration in progress. |
| Learners can see their own value | The field appears read-only on the learner’s own profile page. |
| Learners can edit their own value | The learner can change it. Turning this on also turns on Learners can see their own value. |
- Click Create field.
Leave both learner options off for anything recorded about a learner rather than for them, such as an attrition flag or a salary band. Each field’s row shows a badge for each option you turned on.
Set a value
| Where | Who | Notes |
|---|---|---|
| Create User form | Admin (user:create) | Every active field is on the form, so a required one is filled in from the start |
| Edit on the user’s page | Admin (user:update) | Every active field, whatever its learner options |
| The user’s own profile page | The learner | Only fields they can edit. Fields they can only see show “Managed by your administrator.” |
| CSV import and the REST API | — | One column or JSON key per field |
The user’s page shows the current values in a Custom fields section. It lists every defined field, so a field you added after a user was imported shows as empty rather than missing.
Every change is recorded in the audit log with the before and after values. Clearing a field removes the value rather than storing an empty one.
Turn a dropdown into job roles
A dropdown field such as Job title can drive job roles, the skill levels a person’s work requires. Click Promote to job roles on the field: EmbayLMS creates one job role per option and assigns each person the one matching their value, and the roles then follow the field. Renaming or removing an option, or deleting the field, first tells you what it does to those roles. See Skills & Competencies → Job roles.
What each type accepts
| Type | Accepted | Stored as |
|---|---|---|
| Text | Any text up to 500 characters | As typed, trimmed |
| Number | Any number | Normalised, so 007 and 7 are the same value |
| Date | YYYY-MM-DD | The same date. A day that does not exist (2026-02-30) is refused rather than rolled over |
| Dropdown | One of the defined options, in any letter case | The option’s defined spelling, so sales and Sales never become two values in a report |
| User lookup | A user | A reference to that user |
9 — Importing & exporting users (CSV)
There are two downloads on the Users page, and they answer different questions:
| Button | File | Contains |
|---|---|---|
| ⬇ Export template | users-import-template.csv | The header row only: a blank form to fill in |
| ⬇ Export users | embaylms-users.csv | Every current user, with their values, custom fields included |
Both always include every standard column plus your current custom-field columns. ⬇ Export users has the same columns as the import, so you can export, edit in a spreadsheet and import the same file again.
What ⬇ Export users includes follows what you can already see: an Owner or Admin exports everyone, a Group admin their groups’ members, a Manager their report chain. A very large tenant is capped at 20,000 users per file, and a message tells you when the cap applied.
| Column | Notes |
|---|---|
external_id, email | At least one is required. Used to match existing users |
first_name, last_name, role, locale | Standard profile fields |
user_type | The account type (§7b) |
manager_external_id | Sets the user’s manager, by the manager’s external ID or email. The same relationship as the Manager field in §7b |
group_names | Separated by a pipe (`Sales |
| custom field keys | One column per custom field (e.g. department). Import and the API are not bound by the Required option |
Import: click ⬆ Import CSV, upload the filled file, check the Validation preview, then confirm. Roles, groups and the manager relationship are all applied from the file. Previous imports are listed under Import history on the same page.
10 — SCIM Provisioning
SCIM lets your identity provider (Okta, Entra ID and others) create, update and deactivate EmbayLMS accounts automatically, in step with your HR system.
This is a brief overview. Full setup instructions are in the SCIM Provisioning guide.
How it works:
- You set up EmbayLMS as a SCIM app in your identity provider.
- When someone joins, the identity provider creates their EmbayLMS account.
- When their details change, the identity provider sends the update.
- When they leave, EmbayLMS deactivates the account.
Connection details:
- Go to Settings → User Management → SCIM Provisioning.
- Copy the SCIM base URL.
- Click New Token, name it, then click Create token. Copy the token right away: it is shown only once.
- Enter both in your identity provider’s SCIM app.
10b — External User Types (partners, customers, contractors, volunteers)
Every user has a user type, shown as Account type on their profile. It keeps external audiences apart from employees:
| Type | Typical audience |
|---|---|
| Internal (default) | Employees |
| Partner | Reseller, channel or franchise staff |
| Customer | Client-side learners |
| Contractor | Temporary or agency workers |
| Volunteer | Volunteer workforce |
The type is not a role: it never grants or removes permissions. It is for filtering, targeting and reporting:
- Users list: filter with the type menu (All types shows everyone).
- Dynamic groups: a rule can match User type, e.g. an automatic “All contractors” group.
- Reports: the custom report builder has a User type field, and the REST user-activity report accepts a
user_typefilter. - CSV import: the
user_typecolumn (§1.2). - SCIM: the standard
userTypeattribute is used; unknown values fall back to internal.
Set the type on Create User, with Edit on the user’s page, through the REST API, CSV or SCIM, or with the bulk external flow below.
10c — Bulk-Adding External Users
Onboard an external group (a partner’s staff, a customer’s learners) without SSO, without a migration, and without emailing anyone until you choose to:
- Go to Users and click ⇪ Bulk add external users.
- Under One account per line, paste
email, first name, last namefor each person. Commas, semicolons or tabs all work. Up to 500 lines are read; extra lines are ignored with a warning. - Pick the User type and, optionally, an Account expiry (optional) date.
- Click Validate list and check the result for each line. Lines that match an existing user, match a deactivated user (re-hire them instead, §12) or go over your plan’s seat allowance are refused one by one. The rest go ahead.
- Click the create button. It shows how many accounts will be created. The accounts are created without any email.
- When the group is ready to start, click the invite-wave button. Everyone receives the standard invitation with a set-password link, in one deliberate step. The wave is recorded in the audit log with its counts.
Account expiry: after the expiry date the account can no longer sign in, by any method, and any open session ends. Leave it empty for ongoing access. You can change or clear it later with Edit on the user’s page (Account expires).
Billing: external accounts count toward your plan like any other user. Creating them respects your seat allowance, and per-active-user billing counts them only when they actually sign in.
10d — Login History (per user)
Every user’s page shows a Login history panel: their successful sign-ins, newest first, each with how they signed in (password, SSO, LTI launch or signup auto-login). Anyone who can see the user can see it; Group admins see it only for their groups’ members.
- History starts from the day sign-in tracking was introduced. Earlier sign-ins cannot be shown, and the panel says so when it is empty.
- No IP address or browser details appear here. Those are kept in the audit log only.
- Entries are kept for 24 months.
11 — User Deprovisioning
Deprovisioning removes a person’s access while keeping their learning history for compliance and audit.
11.1 Deactivate a user (recommended)
Deactivation is the standard way to offboard someone. A deactivated user:
- Cannot sign in
- Loses any open session within about 5 minutes
- Keeps their enrollments and full learning record, which still appear in reports
- Can be brought back (see §12)
To deactivate:
- Go to Users and open the person’s page.
- Click Edit.
- Set Status to Inactive.
- Click Save changes.
You cannot deactivate your own account.
SCIM: If you use SCIM, your identity provider deactivates the account automatically when the person is removed from the SCIM app.
11.2 Process a deletion request (irreversible)
When a person asks for their personal information to be erased (for example under Québec’s Law 25), use the Privacy section of their page. It anonymizes the account rather than deleting records outright:
- Their name, email and other personal details are replaced with an anonymous identifier.
- Personal details are removed from audit-log snapshots.
- Completion records and certificates are kept, anonymized, for as long as the retention policy requires. The account is fully removed only when nothing is left under retention.
To process a request:
- Go to Users and open the person’s page.
- In Privacy, click Process deletion request.
- Fill in the Identity verification note: how you confirmed the request came from this person (10 to 500 characters).
- Type
DELETEto confirm (SUPPRIMERwhen your interface is in French). - Click Anonymize permanently.
Warning: This cannot be undone. Use deactivation instead unless you have a data-erasure obligation.
11.3 What deactivation keeps
| Data | Kept after deactivation |
|---|---|
| Course completions and certificates | Yes |
| Assessment scores | Yes |
| Learning history and transcript | Yes |
| Enrollments | Yes, unchanged |
| Audit log entries | Yes |
| Open sessions | No: they end within about 5 minutes |
A deactivated account’s personal details are anonymized automatically 90 days after deactivation (see §12).
12 — Re-Hiring: Restoring a Prior Transcript
When a former employee returns, bring back their original account instead of creating a new one. Their learning history comes back with it.
- Go to Users.
- In the status menu, choose Deactivated. The list shows deactivated accounts.
- Find the person and open their page.
- The re-hire panel at the top shows exactly what will be restored before you commit: enrollments, completions, certifications still valid, certificates, learning-path enrollments and group memberships, all with their original dates. Nothing is recalculated or issued again.
- Click Re-hire this user.
After the re-hire:
- The account can sign in again (password reset or SSO, as configured).
- Recurring and compliance assignments are recalculated against the restored history. A certification that is still valid is not assigned again; expired ones resume their renewal cycle where the dates say they should.
- The action is recorded in the audit log with the number of records restored.
- A
user.reactivatedwebhook fires for integrations.
Re-hire or reactivate? Setting Status back to Active with Edit also lets the person sign in again, but it does not go through the re-hire checks and does not fire the
user.reactivatedwebhook. Use Re-hire this user for a returning employee.
Retention boundary (90 days): a deactivated account is anonymized 90 days after deactivation. After that, it can no longer be re-hired; the re-hire panel shows the exact date. Re-hire returning employees before then, or a new account will be needed.
CSV imports: an import row that matches a deactivated user is refused with a message pointing to the re-hire flow. An import never quietly brings back or duplicates a deactivated account.
If the account was anonymized: it cannot be restored. Create a new account, and bring in past completions with the completions import in the Data Import guide.
13 — Password, Lockout and Session Policies
These settings are at Settings → Security, an Owner-level area. The page has three tabs: Authentication, Passwords & lockout and Access.
13.1 Passwords & lockout
| Setting | Description | Default |
|---|---|---|
| Failed attempts before lock | Wrong passwords in a row before the account is locked. 0 turns lockout off | 0 (off) |
| Lock duration (minutes) | How long a locked account stays locked | 15 |
| Password rotation (days) | Days before a password must be changed. 0 means never | 0 |
Every password must be at least 8 characters. There are no other complexity or reuse rules to configure.
Locked accounts are listed under Locked Accounts on the same tab. Click Unlock next to someone to let them sign in again right away.
SSO tenants: these rules apply only to people who sign in with a password. People who sign in through SSO follow your identity provider’s rules.
13.2 Sessions
On the Access tab, Prevent concurrent sessions has one setting, One active session per user. When it is on, signing in on a new device ends the session on the previous one. It is off by default.
Session length is not configurable.
13.3 Multi-factor authentication (MFA)
On the Authentication tab, under Multi-factor authentication (MFA):
| Setting | Description |
|---|---|
| Enable MFA for this organization | Users who have set up an authenticator app are asked for a code at sign-in. Off by default. |
| Require MFA for these roles | Users with a ticked role must set up MFA. They are never locked out: they see a setup reminder until they do. |
MFA uses an authenticator app (TOTP), such as Google Authenticator or Authy.
To turn MFA on:
- Go to Settings → Security, Authentication tab.
- Turn on Enable MFA for this organization.
- Optionally tick roles under Require MFA for these roles.
- Click Save changes.
Configuration Reference
| Setting | Where | Description | Default |
|---|---|---|---|
| Main role | User page → Edit | One built-in role | Learner |
| Additional roles | User page → Roles | Extra built-in and custom roles | None |
| Group membership | Group page | Manual or dynamic groups | — |
| Manager | User page → Edit | The person the user reports to | — |
| Account type | User page → Edit | Internal or an external type | Internal |
| Status | User page → Edit | Active or Inactive | Active |
| Lockout | Settings → Security → Passwords & lockout | Failed attempts and lock duration | Off |
| Password rotation | Settings → Security → Passwords & lockout | Days before a password must change | Never |
| One session per user | Settings → Security → Access | Ends older sessions on new sign-in | Off |
| MFA | Settings → Security → Authentication | Organization-wide and by role | Off |
| SCIM | Settings → User Management → SCIM Provisioning | Base URL and tokens for your identity provider | — |
Troubleshooting
Creating, importing or reactivating is blocked with an upgrade prompt
Your portal is on the Free plan, which includes up to 5 active users. Deactivate someone to free a seat, or upgrade in Billing: paid plans have no user cap. CSV imports follow the same limit: rows beyond the remaining seats fail with “Seat limit reached for your plan — upgrade to add more users”.
A user cannot sign in with their password
The sign-in page shows “Invalid email or password.” for a wrong password, an unknown email and a deactivated account, so it does not tell you which. Check on the Users page:
- Search for their email. If they are not listed, choose Deactivated in the status menu. A deactivated user can be re-hired (§12).
- If they are not there either, the account does not exist. Create it, or check that SCIM provisioning completed.
A user is told their account is locked
The message is “Your account has been locked. Please contact your administrator.” It only happens when lockout is on (§13.1). Go to Settings → Security → Passwords & lockout, find them under Locked Accounts and click Unlock, or wait for the lock duration to pass.
An SSO user is told their account was not found or is deactivated
“Your account was not found” means no EmbayLMS account matches the email your identity provider sent. Create the account, or check SCIM. “Your account has been deactivated” means the account exists but is inactive (§11, §12).
Your identity provider says the user is not authorized
The user has not been assigned to the EmbayLMS application in your identity provider. Ask your IT administrator to add them to the EmbayLMS SSO application in Okta, Entra ID or your provider.
SSO fails after your identity provider changed its certificate
The sign-in page says the response from your identity provider was invalid. Go to Settings → User Management → SSO / Identity, click Edit on the provider, paste the new certificate into X.509 Certificate (PEM), then click Save configuration. See SAML SSO Setup.
A user has two accounts with different emails
- Choose the account to keep, usually the one with the most learning history.
- On the duplicate’s page, click View full transcript and download it with Export CSV.
- Import those completions into the account you keep with the completions import in the Data Import guide.
- Deactivate the duplicate.
- If both accounts used SSO, make sure your identity provider always sends the same
emailattribute, so future sign-ins land on the right account.
Some rows failed in a CSV import
On the Import users page, find the import under Import history and click Download errors. The file has one line per failed row with the reason in an _errors column, such as “Invalid email” or a role that is not one of the built-in values. A row whose email already exists is not an error: it updates that user. Missing groups are created, not refused.