Download PDF
Download page Create and Manage Users for Tenants.
Create and Manage Users for Tenants
This page provides details for managing Cisco Cloud Observability users through the Accounts Management Portal.
This page focuses on the Cisco Cloud Observability-specific user management options. For details about:
- User status, global role options, and global role permissions, see Manage User Accounts.
- Configuring Single Sign-on (SSO) through Security Assertion Markup Language (SAML), see Configure Single Sign-on Through SAML.
- Setting up Sevice Principals, see Manage Secure Access.
The Accounts Management Portal User Management UI allows Company Admins and License Admins to create, manage, and assign users to Observability Platform tenants. You manage all aspects of the user account exclusively through the Account Management Portal. There are no user management options in the Cisco Observability Platform UI.
Every Cisco AppDynamics user that you register has access toCisco AppDynamics Community for FAQs and user forums. If the user was registered with Cisco Identity (email registered with Cisco), the user also has subscription-based access to Cisco U.
Role Options
Cisco Cloud Observability provides default Observability Platform tenant-specific roles with permissions that define what actions a user can perform. See Assign Roles for Tenants.
There are also several global company roles available. See Role Options.
Create New Users
Follow the steps below to create new users for Observability Platform tenants:
Before You Begin
When creating a new user, Cisco AppDynamics recommends:
Using only ASCII characters for user names and passwords because of browser incompatibilities.
Choosing at least one role for the new user. Although it is possible to assign a role after creation, the user has very limited functionality until a role is assigned.
Only users with Company Admin or License Admin roles can create new users. When we provision a new license for you, we automatically provision a new License Admin user account for that license.
Create a New User
Sign in to your Account Management Portal.
Navigate to Access Management > User Management.
- Select Company Users.
Click and select Add a Single User or Add Multiple Users.
To add a single user, enter the user email and, optionally, the user name.
To add multiple users concurrently, paste or type a list of user emails. The system ignores existing emails.
Click Submit.
If you see the following message, continue to Add Tenants to Users.The user email you entered is owned by another company. This user will be added to your account as a Guest User when you click Next.
- (Optional) Enter the first and last name of the user.
Select an IdP option through Authenticated By:
- Cisco Customer Identity—Cisco acts as the Service Provider. The user name must already exist as a Cisco Identity.
My IdP—the user authenticates through your Service Provider. The user name must already exist in the IdP database.
- Optionally, select one or more Company Roles.
- Company Admin—can create and manage users, assign roles/licenses/Tenants, and configure company preferences.
- Support—can open and manage Support requests with AppDynamics.
License Admin—can view and assign licenses on Controller Tenants to which they have access rights.
If you do not select a role, the user defaults to the Company User role with limited account access. See User Permissions Matrix.
- Click Next.
- Continue to Add Tenants to User.
Add Tenants to User
You can only add tenants to users if you Cisco Observability Platform licenses and associated Observability Platform tenants.
- From Add a User > (2) Assign Tenants, select the tenant names that you want the user to access.
- (Required) Add the user to one or more tenants.
- Click Create & Next.
- From (3) Assign Tenant Roles, click Close.
- Click Assign.
- Continue to Assign Roles to User.
Assign Roles to User
You can only assign users to roles if you Cisco Observability Platform licenses and associated Observability Platform tenants.
- From the Assign Roles dialog, check the desired roles from the Default Roles and Custom Roles tabs.
- Click Save.
- Click Close.
Manage Users
You can create and manage company users and guest users. See User Types to understand the differences.
Company Users
When Cisco AppDynamics deploys a new Observability Platform tenant in your environment, you must assign users to it through the Accounts Management Portal before they can access it. Likewise, when you create a new user, you can assign them to one or more licensed tenants.
- Navigate to Access Management > User Management.
- Select Company Users.
- Select a user and click .
From the Observability Platform Tenant Access panel, click Add FSO Tenant & Role.
- From the Assign Tenant dialog, select a tenant to grant access to the user.
- Click Save.
- From Assign Tenant Roles.
- From Edit User, click Save.
When AppDyanamics deploys a new Observability Platform tenant in your environment, you must assign users to it through the Accounts Management Portal before they can access it. Likewise, when you create a new user, you can assign them to a Tenant and a role.
- Navigate to Access Management > User Management.
- Select Company Users.
- Select a user and click .
- From Observability Platform Tenant Access, click next to the Observability Platform tenant you want to assign roles to the user.
- From the Assign Roles dialog:
- Select the default roles from the Default Roles tab that you want to assign to the user.
- Select the custom roles from the Custom Roles tab that you want to assign to the user.
- Click Save.
- From Edit User, click Save.
The Edit UI allows Company Admins and License Admins to edit Company Roles accordingly. See Company Role Options.
You cannot edit the email address because it is the user's primary system security identification and user name for logging in.
- Navigate to Access Management > User Management.
- Select Company Users.
- Select a user and click .
- Update Basic Information as necessary.
Optionally, update available Company Roles.
Assign or unassign available Observability Platform Licenses and Controller Licenses. Some fields are disabled as Company Admins and License Admins have different rights.
If you select the License Admin role, you must select at least one Observability Platform License Name or Controller License Name to which the user can administer.
A License Admin can only control access to a license to which they have access rights, but they can view other licenses in the company account.
Click Save.
The user you update must refresh their browser to view the edits.
The Edit UI allows Company Admins and License Admins to edit Company Roles accordingly. See Company Role Options.
You cannot edit the email address because it is the user's primary system security identification and user name for logging in.
- Navigate to Access Management > User Management.
- Select Company Users.
- Select two or more users and click .
- From the Access dropdown, select one of the following:
- Change Authenticated Method - You can change the method for authenticating the user to an Identity Provider (IdP) or the Cisco Customer Identity. If you have set up SAML for the user, you will want to select the IdP used for the SAML configuration.
- Select an authentication method for the users.
- Click Primary.
- From the confirmation message, click Click here for more details to view the Status Report dialog.
- Assign Platform Tenants to Selected Users - You can add users to one or more
Observability Platform tenants and assign the users to roles.
- Select the tenants that you want the users to access.
- Click Next.
- Click next to the tenant where you want to assign one or more roles.
- From the Assign Roles dialog:
- Select the default roles from the Default Roles tab that you want to assign to the user.
- Select the custom roles from the Custom Roles tab that you want to assign to the user.
- Click Save.
- Change Authenticated Method - You can change the method for authenticating the user to an Identity Provider (IdP) or the Cisco Customer Identity. If you have set up SAML for the user, you will want to select the IdP used for the SAML configuration.
Click Save.
You can view only users with certain Roles, Statuses, Observability Platform tenants, or Controller Tenant assignments using the Filter panel. If you select multiple Tenants, the filter displays all users for each Tenant cumulatively.
- Navigate to Access Management > User Management.
- Select Company Users.
- Click to open the Filter panel.
- Check the box next to the desired options.
Click Apply.
Inactivating users will prevent them from logging in to any Cisco AppDynamics role-based component, including all associated Tenants.
You can only activate a user that has Inactive status. You can only inactivate a user that has Active status. Pending users do not have Active status by default.
To activate a user:
- Select one or more users with the Inactive status.
- Click .
- Verify that you want to continue.
The user retains access to and related services.
To inactivate a user:
- Select one or more users with the Active status.
- Click .
- Verify that you want to continue.
The user remains inactive until the admin either deletes or deactivates the account.
When you delete a Observability Platform tenant user through the Account Management Portal, the deletion is permanent. However, when you delete a Controller Tenant user through the Controller Tenant UI, their account is still in Active status in the Account Management Portal. This ensures the user can still access other Controller Tenants to which they may have access rights.
Deleting a user in the Account Management Portal is permanent and is not reversible.
You can only delete a user with Inactive status. Users with Active status must be set to Inactive before you can delete them.
- Select one or more users with the Inactive status.
- Click .
- Click Delete to verify the action.
Cisco AppDynamics emails the user notifying them that their account is no longer available.
Guest Users
Guest Users are only available on Observability Platform tenants.
When Cisco AppDynamics deploys a new Observability Platform tenant in your environment, you must assign users to it through the Accounts Management Portal before they can access it. Likewise, when you create a new user, you can assign them to one or more licensed tenants.
- Navigate to Access Management > User Management.
- Select Guest Users.
- Select a user and click .
From the Observability Platform Tenant Access panel, click Add FSO Tenant & Role.
- From the Assign Tenant dialog, select a tenant to grant access to the user.
- Click Save.
- Click Cancel.
- From Edit Guest User, click Save.
When AppDyanamics deploys a new Observability Platform tenant in your environment, you must assign users to it through the Accounts Management Portal before they can access it. Likewise, when you create a new user, you can assign them to a Tenant and a role.
- Navigate to Access Management > User Management.
- Select Guest Users.
- Select a user and click .
- From Observability Platform Tenant Access, click next to the Observability Platform tenant you want to assign roles to the user.
- From the Assign Roles dialog:
- Select the default roles from the Default Roles tab that you want to assign to the user.
- Select the custom roles from the Custom Roles tab that you want to assign to the user.
- Click Save.
- From Edit Guest User, click Save.
You can view only users with certain Roles, Statuses, Observability Platform tenants, or Controller Tenant assignments using the Filter panel. If you select multiple Tenants, the filter displays all users for each Tenant cumulatively.
- Navigate to Access Management > User Management.
- Select Guest Users.
- Click to open the Filter panel.
Check the box next to the desired options.
Click Apply.
You can only remove a Guest User from a tenant. You cannot delete the user permanently. If you accidentally remove a Guest User from a tenant, you can always re-add the Guest User to the tenant.
- Navigate to Access Management > User Management.
- Select Guest Users.
- Select a user and click .
- From the Remove Guest User from Tenant dialog, click Continue.
Cisco AppDynamics emails the user notifying the Guest User that he or she has been removed from the tenant.