User & Role Management
User & Role Management
Manage users who have access to the DuoKey Cockpit
Overview
With DuoKey - DKE, you can manage the users who have access to the DuoKey Cockpit. You can invite, restrict, and delete users using predefined user roles.
Management Portals
Predefined Roles
DuoKey - DKE includes predefined roles as part of your Default Tenant Settings. Three roles are provided and are described below.
| Role | Description |
|---|---|
| DuoKey - Tenant Admin | Customer administrator with full administrative rights within the tenant |
| DuoKey - Auditor | Read-only role for viewing keys, services, and audit/activity logs |
| DuoKey - Host | Reserved for DuoKey personnel for tenant-level support |
DuoKey Cockpit Administrators do not typically need to modify these roles. The default role assigned to a DKE Administrator is DuoKey - Tenant Admin.
Creating Users
The Tenant is an invitation-only system — users cannot self-register.
Open User Management
Navigate to Administration → Users Page
Create New User
Click the Create New User button
Configure Options
Configure the user settings as needed (see options below)
User Configuration Options
| Option | Description |
|---|---|
| Set random password | Sets a random password, which will be displayed in the welcome email |
| Should change password on next login | Requires the user to set a new password upon their first login |
| Send activation email | Sends a verification email to the user's inbox |
| Active | Sets the user as active or inactive |
| Two-factor authentication enabled | Allows the user to configure two-factor authentication |
| Lockout enabled | If enabled, the user will be locked out after too many failed login attempts |
Assigning Roles
For new users, typical roles include:
- DuoKey - Tenant Admin
- DuoKey - Auditor
Important: Do not assign the following system roles: Admin, DuoKey - Host, DKE-Service, or User.
Organization Units
Choose an existing or create a new Organization Unit under Administration → Organization Units.
Configure Multi-Factor Authentication (MFA)
Users can configure two-factor authentication following this guide, including Google Authenticator, FreeOTP, etc.