User management
This section describes how to manage users for your organization.
About users
You add local users so that other members of your organization can use Illumio Segmentation for the Cloud capabilities for their zero-trust segmentation programs. Some users have owner privileges, meaning they can perform the same tasks. All users are assigned a security administrator role that provides them with access to all product capabilities, including the ability to invite additional users. Servers & Endpoints administrative users can see the Access Restriction menu item.
You create local users in Illumio. You do not manage them outside the product using an IdP.
When you become a customer or trial user, you must sign in to add or remove users. For more information, see Signing In.
This first user then sets up additional users. All users can add local users to their organization. Once a user is added to Illumio, they must complete their setup via the Okta activation process.
Add users
Only users with an owner role can add other users.
For best results, Illumio recommends viewing videos in Chrome.
From the left navigation, choose Access > Users. The list of users added to your organization appears.
Click Add. The Add User dialog box appears.
Enter the user's name. Only users see their name displayed in the UI when they sign in.
In the Add User dialog box, enter the user's email address and click Add.
The email address domain must match the domain used by your organization.
The new user enters this email address when they sign in.
Illumio uses this email address in the UI. It displays the user's email address to track user actions in the Events page.
The Add User dialog box closes, and the user list refreshes to include the new user.
What happens next?
After you add a user, they receive an email from Okta with the subject line “Welcome to Okta!” This email provides instructions on how to activate the user's Okta account. Illumio uses Okta for multi-factor authentication.
In addition to the local user account created in Illumio, users have access to an Okta dashboard where they can manage the security that Okta provides for sign-in. The Okta email includes a link to the user's Okta dashboard.
To access your Okta user dashboard, check your Okta email and locate the URL in the line that begins with “Your organization's sign-in page is….”.
For the next steps, see Signing In.
Delete users
Only users with an owner role can delete other users. However, they cannot delete their own user accounts. Not all users have administrative privileges; role-based access is available to Servers & Endpoints users who are not owners.
When a customer or trial user is provisioned access, a primary security administrator email address is associated with that account. This user cannot be deleted.
To delete users:
From the left navigation, choose Access > Users. The list of users added to your organization appears.
Select the users you want to delete.
Click Remove. The Remove User confirmation dialog box appears.
Confirm that you are removing the correct users and click Remove.
Add or remove roles
To add or remove roles, see Role-Based Access Control.