Admin GuidesUser Management

User Management

Plan availability (2026-07-23): managing custom user-field definitions requires the Starter plan or higher. On the Free plan the field-definition page shows an upgrade screen; values already saved on user profiles remain visible in profiles, filters, and CSV exports.

Who this guide is for: Tenant administrators responsible for creating, managing, and deprovisioning users in the EmbayLMS platform.


Overview

EmbayLMS uses role-based access control. You can create users one at a time or import them from a CSV file, give them one or more roles, organize them into groups, and manage their access from first sign-in to offboarding and re-hire.

This guide covers:

  • Creating users and importing them from CSV
  • Built-in roles, custom roles and how roles combine
  • Group Admins and groups (manual and dynamic)
  • The manager relationship and account types
  • Custom user fields
  • SCIM provisioning and external users
  • Deprovisioning and re-hiring
  • Password, lockout, session and MFA settings
  • Troubleshooting

Prerequisites

  • Admin or Owner role on your EmbayLMS tenant (importing users from CSV needs the user:import permission, held by Admin and Owner)
  • A CSV file, if you are importing (see §9)
  • Access to your identity provider, if you use SCIM provisioning (see SCIM Provisioning)

1 — Creating Users

1.1 Create an individual user

  1. Go to Users.
  2. Click Create User.
  3. Enter the user’s First name, Last name and Email address.
  4. Choose a Role (see §2).
  5. Optionally set an Initial password (see the field reference below).
  6. Set the Account type, the Manager and any custom fields your organization uses.
  7. Choose whether to Require password change on first login and whether to Send an invitation email.
  8. Click Create User.

Create User — field reference

FieldRequiredDescription
First nameYesThe user’s given name.
Last nameYesThe user’s family name.
Email addressYesMust be unique within the tenant. Used to sign in.
RoleYesLearner (the default), Manager or Admin. The server only lets you assign a role at your own level or below. To give Instructor, Group admin, E-commerce admin or a custom role, create the user first, then use the Roles panel on their page (§3.2).
Account typeNoInternal (the default), Partner, Customer, Contractor or Volunteer. See §7b.
ManagerNoThe person this user reports to. See §7b.
Custom fieldsDependsEvery active custom field appears. A field marked Required must be filled in. See §8.
Initial passwordNoA starting password, at least 8 characters. Leave it empty to have the user set their own password from an emailed link. The password is hashed and never shown again, so share it through a secure channel.
Require password change on first loginNoThe user must choose a new password the first time they sign in. Only available when you set an initial password.
Send an invitation emailNo (on by default)Emails the user a welcome message. If you set a password, the email links to the sign-in page. If you did not, it carries a set-your-password link valid for 7 days.

Which combination to use:

GoalInitial passwordRequire changeSend email
Let the user set their own password (classic invite)empty—On
Hand a user a temporary password in person or through a secure channelSet itOn (recommended)Optional
Provision a shared or service account with a fixed passwordSet itOffOff

The password is never included in the email or in any log. When Require password change on first login is set, the user sees a full-screen prompt to choose a new password right after their first sign-in, and cannot reach the app until they do.

SSO tenants: If your tenant enforces SSO, users sign in through SSO rather than with a password. Leave the initial password empty. The invitation email still tells the user their account exists.

1.2 Import users from CSV

  1. Go to Users and click ⬆ Import CSV. The Import users page opens (Admin and Owner only, user:import).
  2. To start from a blank file with the right headers, click ⬇ Export template on the Users page (see §9).
  3. Prepare your file with these columns:
ColumnRequiredDescription
external_idOne of external_id / emailStable identifier from your HR or source system. Used first to match existing users.
emailOne of external_id / emailUnique in the tenant. Needed to create a new user.
first_nameNo
last_nameNo
roleNoOne built-in role: learner (default), instructor, manager, group_admin, ecommerce_admin, admin or owner. The legacy author is still accepted. Custom roles are not accepted here.
localeNoen (default) or fr-CA
user_typeNointernal, partner, customer, contractor or volunteer. Empty keeps the current value on update and means internal on create.
manager_external_idNoThe external_id of the user’s manager, or their email. Resolved after every row is created.
group_namesNoGroup names separated by a pipe, e.g. Sales|Ontario. Missing groups are created as manual groups.
custom field keysNoOne column per custom field (e.g. department). See §8.
  1. Choose your file under CSV file and click Validate.
  2. The Validation preview lists each row with its errors. Nothing is saved yet.
  3. Fix the errors and upload again, or go ahead: rows with errors are skipped.
  4. Click the import button. It shows how many rows will be imported. The import runs in the background.
  5. When it finishes, you receive an email with the number of rows imported and the number that failed.

Limit: A single CSV file can be up to about 8 MB. For larger or continuous imports, split the file or use SCIM provisioning. Full column reference and troubleshooting: Data Import guide.


2 — Built-in Roles

EmbayLMS has seven built-in roles. Roles add up: a user with several roles has every permission of each (see §4). The Instructor, Manager and Group admin roles are scoped: they only reach the courses, people or groups they are tied to.

RoleScopeWhat it is for
LearnerThemselvesBrowse the catalog, self-enroll where offered, attend training, follow their own progress and credentials. The default role.
InstructorAssigned coursesEdit content, run in-person and virtual sessions, grade, and see analytics for the courses they are assigned to (course editor → Instructors tab).
ManagerTheir report chainSee progress and analytics for everyone who reports to them, directly or indirectly (through the Manager field). Can also enroll their reports in courses and sessions. Cannot export reports or edit profiles.
Group adminAssigned groupsCreate and deactivate members of their groups, manage their enrollments and group membership, and see and export group reports. Cannot edit profile details such as custom fields, account type or manager.
E-commerce adminTenantThe whole E-commerce area: pricing, coupons, orders, refunds, revenue, storefront. Apart from the Owner, no other role gets e-commerce by default.
AdminTenantDay-to-day administration of the whole tenant, including Roles and Permissions and importing users, but not Billing or the Settings area.
OwnerTenantEverything an Admin can do, plus the whole Settings area and Billing. Every tenant always has at least one Owner.

The Author role is retired. Tenant-wide content authoring is Admin or Owner; course-scoped content editing is Instructor. Former authors were moved to a pre-built custom role named “Content Author” that keeps their previous permissions.

For the full permission matrix and the rules for assigning roles, see Roles and Permissions.


3 — Custom Roles

Custom roles let you define a precise set of permissions beyond the built-in roles. For example, a “Compliance Officer” role that can see compliance reports and nothing else.

3.1 Create a custom role

  1. Go to Settings → User Management → Roles and Permissions. The page is titled Custom Roles.
  2. Click New role, or Clone on any existing role to start from its permissions.
  3. Enter a Role name (e.g., “Compliance Officer”).
  4. Tick the permissions you need under Permission scopes. They are grouped by area, for example user:view, course:edit, enrollment:create, report:view, report:export. You cannot grant a permission you do not hold yourself: those boxes are greyed out.
  5. Click Save.

See Roles and Permissions for the full permission catalog.

3.2 Give a user more roles

  1. Open the user’s page (Users → click their name).
  2. Find the Roles panel.
  3. Tick the roles to add under Additional built-in roles and Custom roles.
  4. Click Save roles.

The user’s main role is changed separately, with Edit on their page.

3.3 Edit or delete a custom role

  • To edit: on the Roles and Permissions page, click Edit on the role’s row. The editor opens on the same page.
  • To delete: click Delete on the role’s row. A confirmation says how many people hold the role; click Delete again to confirm. The role is removed from every user who held it, and this cannot be undone.

Built-in roles are read-only: you can clone them, but not change or delete them.


4 — Role Cumulation

A user can hold more than one role at a time. Their permissions are the union of the permissions of every role they hold.

Example:

  • A user holds both Instructor and Manager.
  • They can do everything an Instructor can do (edit content, schedule sessions and grade in their assigned courses) and everything a Manager can do (follow the progress of their report chain).

Key rules:

  • There is no conflict between roles: the most permissive access wins.
  • Combining roles never widens a scope. Instructor rights stay limited to the assigned courses, and Group admin rights to the assigned groups.
  • A user with Learner plus Admin has full day-to-day admin access, because Admin grants tenant-wide permissions. Settings and Billing remain Owner-only.
  • Every role grant and removal is recorded in the audit log.

5 — Group Admin Role: Scoping and Assignment

A Group admin’s reach is tied to the groups they are assigned, not to the whole tenant. Two things are needed:

  1. The user must hold the Group admin role, as their main role or as an additional role (§3.2).
  2. They must be assigned to one or more groups, as below.

An assignment without the role has no effect.

5.1 Assign a Group admin to a group

From the groups list (Admin and Owner):

  1. Go to Groups. The Admins column shows who administers each group.
  2. Click Manage on the group’s row. A panel lists the Current admins, each with Remove.
  3. In Add a group admin, type at least two characters of a name or email and pick the person from the list (a click, or the arrow keys and Enter). People who already administer the group are not offered.
  4. Click Assign.

From the user’s page: open the user and use the Group Admin Assignments panel to add a group. Only Admins and Owners can make assignments.

Both paths do the same thing and are recorded in the audit log. A Group admin who opens the groups list sees the admins of their own groups only.

5.2 What Group admins can see and do

ActionAllowed
See members of their assigned groupsYes
Create and deactivate members of those groupsYes
Enroll group members in coursesYes
Export progress reports for their groupsYes
Add or remove members of their groupsYes
Edit a member’s profile details (custom fields, account type, manager)No
See users outside their groupsNo
Edit coursesNo
Open the Settings areaNo
See tenant-wide reportsNo

6 — Managing Groups

Groups organize users for reporting, enrollment and scoping. There are two types: Manual groups, whose members you add yourself or by CSV, and Dynamic groups, whose members follow rules and update automatically.

The Groups page lists every group with the columns Name, Description, Type (Manual or Dynamic), Members and Admins, and View and Edit on each row.

6.1 Create a manual group

  1. Go to Groups and click New Group.
  2. Enter a Name and, optionally, a Description.
  3. Leave the dynamic-group box unticked.
  4. Click New Group at the bottom of the form.
  5. On the group’s page, click Add Member. In People to add, search and pick each person (up to 50 at a time; people already in the group are not offered), then click the add button, which shows how many people you picked. If someone cannot be added, the dialog says how many were added and keeps the others selected so you can try again. To add many people at once, use a CSV file with the group_names column (§1.2) or the group-members import in the Data Import guide.

6.2 Create a dynamic group

A dynamic group includes every user who matches its rules.

  1. Go to Groups and click New Group.
  2. Enter a Name, then tick Dynamic group (auto-membership by rules) to show the rule builder.
  3. Build each condition:
    • The attribute: Role, Language, Timezone, Email domain or User type.
    • is or is not.
    • The value, for example en or acme.com.
  4. Click + Add condition for more, and choose whether members must match all conditions or any condition.
  5. Click New Group. Membership is filled from the rules and kept up to date as user details change.

6.3 Edit a group

On the Groups page, click Edit on a row:

  • The Name and Description can be changed for every group.
  • A dynamic group also shows its rules. Saving changed rules updates the membership right away: users who no longer match are removed, and newly matching users are added.
  • The type cannot change after creation. To switch between manual and dynamic, create a new group.

6.4 Manage group membership

  • Add people to a manual group: open the group and click Add Member.
  • Remove someone: click Remove next to their name. People added by SCIM or by your identity provider are managed there and cannot be removed here.
  • Dynamic groups: the member list is read-only. Change the user’s details or the group’s rules (§6.3) to change who is in it. Re-sync members refreshes the list on demand.

7 — Organizational Hierarchy

The organization chart in EmbayLMS is built from one thing: the Manager field on each user. There is no separate department structure.

FeatureHow the manager relationship is used
Team Roster (the manager’s team view)Shows everyone in the manager’s report chain, directly or indirectly
Overdue escalation emailsSent to the manager of a learner who is overdue
Report scopingA Manager sees only their own chain

Set a user’s manager as described in §7b, or with the manager_external_id CSV column.

Department is a custom text field that every tenant starts with. It is useful for filtering, reports and CSV exports, but it does not affect who reports to whom. Set it with Edit on the user’s page or with the department CSV column.


7b — Account type and manager

Two details live on every user beside their role. Both can be set on Create User and changed later with Edit on the user’s page. Changing them needs the user:update permission, which Admins and Owners have.

Account type

TypeUse
InternalAn employee. The default.
Partner, Customer, Contractor, VolunteerEveryone else, for filtering, targeting and reporting

Account type is not a permission. It never changes what someone can do: the role does that. Use it to answer questions like “how many contractors completed the safety course”, to filter the Users list, and to report by audience.

In the Edit User panel, choosing an external type shows Account expires. From that date, sign-in is refused and any open session ends. Leave it empty for no expiry. The field is hidden for Internal, and switching back to Internal clears it.

Manager

Manager is the people-manager relationship, and it matters:

  • it decides whose records a user with the Manager role can see (their report chain),
  • it decides who receives the overdue-training digest for a learner, and
  • it drives the manager’s team view.

Set it with the Manager search field: type at least two characters of a name or email, pick the person from the list (arrow keys and Enter work too), and they appear in a box with a Clear button to take them off. The person being edited is never offered as their own manager, and two things are refused when you save:

RefusedWhy
Making someone their own managerThey would be their own escalation target
Choosing someone who already reports to this user, at any depthIt would create a loop in the org chart

Reading the chain

  • The user’s page shows their Manager as a link, so you can walk up one click at a time.
  • A manager’s own page lists their direct reports, each linked, with View the whole team → for everyone beneath them at any depth.
  • The Users list has a Manager column. When you follow a team link, the list says which filter is on and offers Show all users.

Both changes are recorded in the audit log with the before and after values.


8 — Custom user fields

Add extra fields to every user, up to 50 per tenant. Two fields come built in and do not count toward the 50: Department (text) and Manager (the people-manager relationship in §7b).

Define a field

  1. Go to Users and click ⚙ Custom fields.
  2. The counter at the top shows how many of the 50 slots are used and how many remain.
  3. Click + New field, enter a label, choose a type (text, number, date, dropdown or user lookup) and, for a dropdown, its options.
  4. Choose how the field behaves. All three options are off by default:
OptionEffect
RequiredMust be filled in on Create User and in the Edit User panel. It is deliberately not enforced on CSV import or the API, so adding a required field never blocks a migration in progress.
Learners can see their own valueThe field appears read-only on the learner’s own profile page.
Learners can edit their own valueThe learner can change it. Turning this on also turns on Learners can see their own value.
  1. Click Create field.

Leave both learner options off for anything recorded about a learner rather than for them, such as an attrition flag or a salary band. Each field’s row shows a badge for each option you turned on.

Set a value

WhereWhoNotes
Create User formAdmin (user:create)Every active field is on the form, so a required one is filled in from the start
Edit on the user’s pageAdmin (user:update)Every active field, whatever its learner options
The user’s own profile pageThe learnerOnly fields they can edit. Fields they can only see show “Managed by your administrator.”
CSV import and the REST API—One column or JSON key per field

The user’s page shows the current values in a Custom fields section. It lists every defined field, so a field you added after a user was imported shows as empty rather than missing.

Every change is recorded in the audit log with the before and after values. Clearing a field removes the value rather than storing an empty one.

Turn a dropdown into job roles

A dropdown field such as Job title can drive job roles, the skill levels a person’s work requires. Click Promote to job roles on the field: EmbayLMS creates one job role per option and assigns each person the one matching their value, and the roles then follow the field. Renaming or removing an option, or deleting the field, first tells you what it does to those roles. See Skills & Competencies → Job roles.

What each type accepts

TypeAcceptedStored as
TextAny text up to 500 charactersAs typed, trimmed
NumberAny numberNormalised, so 007 and 7 are the same value
DateYYYY-MM-DDThe same date. A day that does not exist (2026-02-30) is refused rather than rolled over
DropdownOne of the defined options, in any letter caseThe option’s defined spelling, so sales and Sales never become two values in a report
User lookupA userA reference to that user

9 — Importing & exporting users (CSV)

There are two downloads on the Users page, and they answer different questions:

ButtonFileContains
⬇ Export templateusers-import-template.csvThe header row only: a blank form to fill in
⬇ Export usersembaylms-users.csvEvery current user, with their values, custom fields included

Both always include every standard column plus your current custom-field columns. ⬇ Export users has the same columns as the import, so you can export, edit in a spreadsheet and import the same file again.

What ⬇ Export users includes follows what you can already see: an Owner or Admin exports everyone, a Group admin their groups’ members, a Manager their report chain. A very large tenant is capped at 20,000 users per file, and a message tells you when the cap applied.

ColumnNotes
external_id, emailAt least one is required. Used to match existing users
first_name, last_name, role, localeStandard profile fields
user_typeThe account type (§7b)
manager_external_idSets the user’s manager, by the manager’s external ID or email. The same relationship as the Manager field in §7b
group_namesSeparated by a pipe (`Sales
custom field keysOne column per custom field (e.g. department). Import and the API are not bound by the Required option

Import: click ⬆ Import CSV, upload the filled file, check the Validation preview, then confirm. Roles, groups and the manager relationship are all applied from the file. Previous imports are listed under Import history on the same page.


10 — SCIM Provisioning

SCIM lets your identity provider (Okta, Entra ID and others) create, update and deactivate EmbayLMS accounts automatically, in step with your HR system.

This is a brief overview. Full setup instructions are in the SCIM Provisioning guide.

How it works:

  1. You set up EmbayLMS as a SCIM app in your identity provider.
  2. When someone joins, the identity provider creates their EmbayLMS account.
  3. When their details change, the identity provider sends the update.
  4. When they leave, EmbayLMS deactivates the account.

Connection details:

  • Go to Settings → User Management → SCIM Provisioning.
  • Copy the SCIM base URL.
  • Click New Token, name it, then click Create token. Copy the token right away: it is shown only once.
  • Enter both in your identity provider’s SCIM app.

10b — External User Types (partners, customers, contractors, volunteers)

Every user has a user type, shown as Account type on their profile. It keeps external audiences apart from employees:

TypeTypical audience
Internal (default)Employees
PartnerReseller, channel or franchise staff
CustomerClient-side learners
ContractorTemporary or agency workers
VolunteerVolunteer workforce

The type is not a role: it never grants or removes permissions. It is for filtering, targeting and reporting:

  • Users list: filter with the type menu (All types shows everyone).
  • Dynamic groups: a rule can match User type, e.g. an automatic “All contractors” group.
  • Reports: the custom report builder has a User type field, and the REST user-activity report accepts a user_type filter.
  • CSV import: the user_type column (§1.2).
  • SCIM: the standard userType attribute is used; unknown values fall back to internal.

Set the type on Create User, with Edit on the user’s page, through the REST API, CSV or SCIM, or with the bulk external flow below.


10c — Bulk-Adding External Users

Onboard an external group (a partner’s staff, a customer’s learners) without SSO, without a migration, and without emailing anyone until you choose to:

  1. Go to Users and click ⇪ Bulk add external users.
  2. Under One account per line, paste email, first name, last name for each person. Commas, semicolons or tabs all work. Up to 500 lines are read; extra lines are ignored with a warning.
  3. Pick the User type and, optionally, an Account expiry (optional) date.
  4. Click Validate list and check the result for each line. Lines that match an existing user, match a deactivated user (re-hire them instead, §12) or go over your plan’s seat allowance are refused one by one. The rest go ahead.
  5. Click the create button. It shows how many accounts will be created. The accounts are created without any email.
  6. When the group is ready to start, click the invite-wave button. Everyone receives the standard invitation with a set-password link, in one deliberate step. The wave is recorded in the audit log with its counts.

Account expiry: after the expiry date the account can no longer sign in, by any method, and any open session ends. Leave it empty for ongoing access. You can change or clear it later with Edit on the user’s page (Account expires).

Billing: external accounts count toward your plan like any other user. Creating them respects your seat allowance, and per-active-user billing counts them only when they actually sign in.

10d — Login History (per user)

Every user’s page shows a Login history panel: their successful sign-ins, newest first, each with how they signed in (password, SSO, LTI launch or signup auto-login). Anyone who can see the user can see it; Group admins see it only for their groups’ members.

  • History starts from the day sign-in tracking was introduced. Earlier sign-ins cannot be shown, and the panel says so when it is empty.
  • No IP address or browser details appear here. Those are kept in the audit log only.
  • Entries are kept for 24 months.

11 — User Deprovisioning

Deprovisioning removes a person’s access while keeping their learning history for compliance and audit.

Deactivation is the standard way to offboard someone. A deactivated user:

  • Cannot sign in
  • Loses any open session within about 5 minutes
  • Keeps their enrollments and full learning record, which still appear in reports
  • Can be brought back (see §12)

To deactivate:

  1. Go to Users and open the person’s page.
  2. Click Edit.
  3. Set Status to Inactive.
  4. Click Save changes.

You cannot deactivate your own account.

SCIM: If you use SCIM, your identity provider deactivates the account automatically when the person is removed from the SCIM app.

11.2 Process a deletion request (irreversible)

When a person asks for their personal information to be erased (for example under Québec’s Law 25), use the Privacy section of their page. It anonymizes the account rather than deleting records outright:

  • Their name, email and other personal details are replaced with an anonymous identifier.
  • Personal details are removed from audit-log snapshots.
  • Completion records and certificates are kept, anonymized, for as long as the retention policy requires. The account is fully removed only when nothing is left under retention.

To process a request:

  1. Go to Users and open the person’s page.
  2. In Privacy, click Process deletion request.
  3. Fill in the Identity verification note: how you confirmed the request came from this person (10 to 500 characters).
  4. Type DELETE to confirm (SUPPRIMER when your interface is in French).
  5. Click Anonymize permanently.

Warning: This cannot be undone. Use deactivation instead unless you have a data-erasure obligation.

11.3 What deactivation keeps

DataKept after deactivation
Course completions and certificatesYes
Assessment scoresYes
Learning history and transcriptYes
EnrollmentsYes, unchanged
Audit log entriesYes
Open sessionsNo: they end within about 5 minutes

A deactivated account’s personal details are anonymized automatically 90 days after deactivation (see §12).


12 — Re-Hiring: Restoring a Prior Transcript

When a former employee returns, bring back their original account instead of creating a new one. Their learning history comes back with it.

  1. Go to Users.
  2. In the status menu, choose Deactivated. The list shows deactivated accounts.
  3. Find the person and open their page.
  4. The re-hire panel at the top shows exactly what will be restored before you commit: enrollments, completions, certifications still valid, certificates, learning-path enrollments and group memberships, all with their original dates. Nothing is recalculated or issued again.
  5. Click Re-hire this user.

After the re-hire:

  • The account can sign in again (password reset or SSO, as configured).
  • Recurring and compliance assignments are recalculated against the restored history. A certification that is still valid is not assigned again; expired ones resume their renewal cycle where the dates say they should.
  • The action is recorded in the audit log with the number of records restored.
  • A user.reactivated webhook fires for integrations.

Re-hire or reactivate? Setting Status back to Active with Edit also lets the person sign in again, but it does not go through the re-hire checks and does not fire the user.reactivated webhook. Use Re-hire this user for a returning employee.

Retention boundary (90 days): a deactivated account is anonymized 90 days after deactivation. After that, it can no longer be re-hired; the re-hire panel shows the exact date. Re-hire returning employees before then, or a new account will be needed.

CSV imports: an import row that matches a deactivated user is refused with a message pointing to the re-hire flow. An import never quietly brings back or duplicates a deactivated account.

If the account was anonymized: it cannot be restored. Create a new account, and bring in past completions with the completions import in the Data Import guide.


13 — Password, Lockout and Session Policies

These settings are at Settings → Security, an Owner-level area. The page has three tabs: Authentication, Passwords & lockout and Access.

13.1 Passwords & lockout

SettingDescriptionDefault
Failed attempts before lockWrong passwords in a row before the account is locked. 0 turns lockout off0 (off)
Lock duration (minutes)How long a locked account stays locked15
Password rotation (days)Days before a password must be changed. 0 means never0

Every password must be at least 8 characters. There are no other complexity or reuse rules to configure.

Locked accounts are listed under Locked Accounts on the same tab. Click Unlock next to someone to let them sign in again right away.

SSO tenants: these rules apply only to people who sign in with a password. People who sign in through SSO follow your identity provider’s rules.

13.2 Sessions

On the Access tab, Prevent concurrent sessions has one setting, One active session per user. When it is on, signing in on a new device ends the session on the previous one. It is off by default.

Session length is not configurable.

13.3 Multi-factor authentication (MFA)

On the Authentication tab, under Multi-factor authentication (MFA):

SettingDescription
Enable MFA for this organizationUsers who have set up an authenticator app are asked for a code at sign-in. Off by default.
Require MFA for these rolesUsers with a ticked role must set up MFA. They are never locked out: they see a setup reminder until they do.

MFA uses an authenticator app (TOTP), such as Google Authenticator or Authy.

To turn MFA on:

  1. Go to Settings → Security, Authentication tab.
  2. Turn on Enable MFA for this organization.
  3. Optionally tick roles under Require MFA for these roles.
  4. Click Save changes.

Configuration Reference

SettingWhereDescriptionDefault
Main roleUser page → EditOne built-in roleLearner
Additional rolesUser page → RolesExtra built-in and custom rolesNone
Group membershipGroup pageManual or dynamic groups—
ManagerUser page → EditThe person the user reports to—
Account typeUser page → EditInternal or an external typeInternal
StatusUser page → EditActive or InactiveActive
LockoutSettings → Security → Passwords & lockoutFailed attempts and lock durationOff
Password rotationSettings → Security → Passwords & lockoutDays before a password must changeNever
One session per userSettings → Security → AccessEnds older sessions on new sign-inOff
MFASettings → Security → AuthenticationOrganization-wide and by roleOff
SCIMSettings → User Management → SCIM ProvisioningBase URL and tokens for your identity provider—

Troubleshooting

Creating, importing or reactivating is blocked with an upgrade prompt

Your portal is on the Free plan, which includes up to 5 active users. Deactivate someone to free a seat, or upgrade in Billing: paid plans have no user cap. CSV imports follow the same limit: rows beyond the remaining seats fail with “Seat limit reached for your plan — upgrade to add more users”.

A user cannot sign in with their password

The sign-in page shows “Invalid email or password.” for a wrong password, an unknown email and a deactivated account, so it does not tell you which. Check on the Users page:

  • Search for their email. If they are not listed, choose Deactivated in the status menu. A deactivated user can be re-hired (§12).
  • If they are not there either, the account does not exist. Create it, or check that SCIM provisioning completed.

A user is told their account is locked

The message is “Your account has been locked. Please contact your administrator.” It only happens when lockout is on (§13.1). Go to Settings → Security → Passwords & lockout, find them under Locked Accounts and click Unlock, or wait for the lock duration to pass.

An SSO user is told their account was not found or is deactivated

“Your account was not found” means no EmbayLMS account matches the email your identity provider sent. Create the account, or check SCIM. “Your account has been deactivated” means the account exists but is inactive (§11, §12).

Your identity provider says the user is not authorized

The user has not been assigned to the EmbayLMS application in your identity provider. Ask your IT administrator to add them to the EmbayLMS SSO application in Okta, Entra ID or your provider.

SSO fails after your identity provider changed its certificate

The sign-in page says the response from your identity provider was invalid. Go to Settings → User Management → SSO / Identity, click Edit on the provider, paste the new certificate into X.509 Certificate (PEM), then click Save configuration. See SAML SSO Setup.

A user has two accounts with different emails

  1. Choose the account to keep, usually the one with the most learning history.
  2. On the duplicate’s page, click View full transcript and download it with Export CSV.
  3. Import those completions into the account you keep with the completions import in the Data Import guide.
  4. Deactivate the duplicate.
  5. If both accounts used SSO, make sure your identity provider always sends the same email attribute, so future sign-ins land on the right account.

Some rows failed in a CSV import

On the Import users page, find the import under Import history and click Download errors. The file has one line per failed row with the reason in an _errors column, such as “Invalid email” or a role that is not one of the built-in values. A row whose email already exists is not an error: it updates that user. Missing groups are created, not refused.