Skip to main content

User & Role Management

Applies to:
User InvitationsRole AssignmentOrganization UnitsMFA Configuration

Overview​

With DuoKey - DKE, you can manage the users who have access to the DuoKey Cockpit. You can invite, restrict, and delete users using predefined user roles.

Management Portals

1
Log in to DuoKey Cockpitcockpit.duokey.cloud
2
User ManagementAdministration → Users Page
3
Role ManagementAdministration → Roles Page

Predefined Roles​

DuoKey - DKE includes predefined roles as part of your Default Tenant Settings. Three roles are provided and are described below.

RoleDescription
DuoKey - Tenant AdminCustomer administrator with full administrative rights within the tenant
DuoKey - AuditorRead-only role for viewing keys, services, and audit/activity logs
DuoKey - HostReserved for DuoKey personnel for tenant-level support
Note

DuoKey Cockpit Administrators do not typically need to modify these roles. The default role assigned to a DKE Administrator is DuoKey - Tenant Admin.

Creating Users​

The Tenant is an invitation-only system — users cannot self-register.

1

Open User Management

Navigate to Administration → Users Page

2

Create New User

Click the Create New User button

3

Configure Options

Configure the user settings as needed (see options below)

User Configuration Options​

OptionDescription
Set random passwordSets a random password, which will be displayed in the welcome email
Should change password on next loginRequires the user to set a new password upon their first login
Send activation emailSends a verification email to the user's inbox
ActiveSets the user as active or inactive
Two-factor authentication enabledAllows the user to configure two-factor authentication
Lockout enabledIf enabled, the user will be locked out after too many failed login attempts

Assigning Roles​

For new users, typical roles include:

  • DuoKey - Tenant Admin
  • DuoKey - Auditor
Warning

Important: Do not assign the following system roles: Admin, DuoKey - Host, DKE-Service, or User.

Organization Units​

Choose an existing or create a new Organization Unit under Administration → Organization Units.

Configure Multi-Factor Authentication (MFA)​

Users can configure two-factor authentication following this guide, including Google Authenticator, FreeOTP, etc.