πŸ“‹ Unlocking users in the FTAPI platform

This guide shows administrators how to determine the cause of an account lockout and how to safely reactivate affected users in the FTAPI platform.

Overview: When is a user considered "locked"?

Typical causes include:

  • A: Trial license expired
  • B: Brute-force protection triggered after too many failed attempts
  • C: IdP control (SAML/LDAP) revoked the authorization
  • D: Manual deactivation or cleanup rule

Case A: Trial license expired

Check the user's group membership and the availability of licenses. To restore access, follow these steps:

  1. Check for available licenses; these are assigned automatically if available.
  2. Deactivate licensed accounts that are no longer needed to free up licenses.
  3. Purchase additional licenses if necessary.
  4. Move the user into a license-free group (e.g., "Guest") so that basic functions become available again.

Important note: When deleting a user account, data in SecuRooms that is accessed exclusively by this user will be irretrievably lost.

Case B: Brute-force protection

If "Lock affected account" is active, the FTAPI platform locks the account as soon as the defined maximum number of failed attempts is reached. The reset time interval determines when individual failed attempts expire. Keep the default values unless there is a valid reason for adjustments.

Avoiding failed logins

  • SAML users must use the SAML-Login button exclusively.
  • Standard users log in with username and password.
  • Remove outdated access data saved by the browser (autofill) and clear the cache.

Case C: IdP (SAML/LDAP) – automatic reactivation

For SAML/LDAP accounts, the Identity Provider (e.g., Microsoft Azure AD) manages passwords and access rights. A deactivated SAML/LDAP account is automatically reactivated upon the next successful login via the IdP. If you wish to prevent reactivation, revoke the corresponding roles directly in the IdP.

Case D: Manual deactivation or cleanup rules

Check whether the account was deactivated manually or if a cleanup rule has been applied. Resolve the cause and ensure that the group membership and license assignment match the desired usage.

Note for end users after reactivation

After every new login, you must reactivate end-to-end encryption by re-entering your SecuPass.

Related articles

❓ License management: Understanding and managing trial licenses 

πŸ“‹ System: Configuring brute-force protection 

User and group management in FTAPI 

πŸ“‹ Group management: Configuring permissions, licenses, and priority rules