π Unlocking users in the FTAPI platform
Overview: When is a user considered "locked"?
Typical causes include:
- A: Trial license expired
- B: Brute-force protection triggered after too many failed attempts
- C: IdP control (SAML/LDAP) revoked the authorization
- D: Manual deactivation or cleanup rule
Case A: Trial license expired
Check the user's group membership and the availability of licenses. To restore access, follow these steps:
- Check for available licenses; these are assigned automatically if available.
- Deactivate licensed accounts that are no longer needed to free up licenses.
- Purchase additional licenses if necessary.
- Move the user into a license-free group (e.g., "Guest") so that basic functions become available again.
Important note: When deleting a user account, data in SecuRooms that is accessed exclusively by this user will be irretrievably lost.
Case B: Brute-force protection
If "Lock affected account" is active, the FTAPI platform locks the account as soon as the defined maximum number of failed attempts is reached. The reset time interval determines when individual failed attempts expire. Keep the default values unless there is a valid reason for adjustments.
Avoiding failed logins
- SAML users must use the
SAML-Loginbutton exclusively. - Standard users log in with username and password.
- Remove outdated access data saved by the browser (autofill) and clear the cache.
Case C: IdP (SAML/LDAP) β automatic reactivation
For SAML/LDAP accounts, the Identity Provider (e.g., Microsoft Azure AD) manages passwords and access rights. A deactivated SAML/LDAP account is automatically reactivated upon the next successful login via the IdP. If you wish to prevent reactivation, revoke the corresponding roles directly in the IdP.
Case D: Manual deactivation or cleanup rules
Check whether the account was deactivated manually or if a cleanup rule has been applied. Resolve the cause and ensure that the group membership and license assignment match the desired usage.
Note for end users after reactivation
After every new login, you must reactivate end-to-end encryption by re-entering your SecuPass.
Related articles
β License management: Understanding and managing trial licenses
π System: Configuring brute-force protection
User and group management in FTAPI
π Group management: Configuring permissions, licenses, and priority rules