Overview
This article explains the procedure for Access Control administrators to create or edit users from the Access Control Administration.
Notes
- The content of this article is based on product specifications as of August 2026 and is subject to change without notice.
- Global administrator privileges for Access Control are required to view the actual screens or make configuration changes.
- For instructions on how to access the Administration, please refer to the following article.
How to Access the Access Control Administration - If you are synchronizing users from Active Directory to Access Control, this operation is not required.
Procedure
Create or Edit Users Individually
-
From the Access Control Administration, go to [Users] – [User List].
-
Click the [+Add] button in the upper right, or select a user from the User List to edit.
For instructions on searching for registered users, please refer to the following article.
Search for Users -
Enter or edit each field, then click [Save] or [Save Changes] in the lower right.
For details on each field, see Fields (Create/Edit User).
Create or Edit Users in Bulk
For details, please refer to the following articles.
Bulk User Registration
Bulk Update of Access Control Users
Fields (Create/Edit User)
When creating or editing a user, please check and prepare the following information in advance.
| Field | Description | Notes |
| Username | A unique value to identify the user in Access Control |
This is the value the user enters on the Access Control [Access Control] Appearance.
The "Username" cannot be changed after creation. |
| Family name | User's [Family name] information |
Up to 256 characters.
|
| Given name | User's [Given name] information | Up to 256 characters. *1 (same as above) |
| Display name | User's [Display name] information | Up to 256 characters. *1 (same as above) |
| Login ID UserPrincipalName *Only when linked with Microsoft 365 |
User's [UserPrincipalName] information |
・This is the login ID used to log in to HENNGE One. ・Set the same value as the UserPrincipalName for this user in Microsoft 365. *Only authentication domains in Access Control can be registered. |
| Login ID Email address (SAML UID) *Only when linked with Google Workspace |
User's [Email address] information |
・This is the login ID used to log in to HENNGE One. ・Set the same value as the email address for this user in Google Workspace. |
| Microsoft Immutable ID | Microsoft 365 user identifier | ・This identifier is used to uniquely link user accounts in Microsoft 365. ・Cannot be edited from the Administration. |
| Synchronization | Setting to exclude the user from groupware user synchronization |
If you are synchronizing users with Google Workspace or Microsoft 365 in [Provisioning Settings], you can specify whether this user is included in synchronization.
*In Google provisioning, if there are available Google Workspace licenses and you uncheck the exclusion, the user information in Access Control will be provisioned immediately. *This setting controls user synchronization between Access Control and services. This setting alone does not exclude the user from SSO integration. |
| Custom User Attributes | User's [Custom User Attributes] information |
If [Custom User Attributes] have been created in advance, you can edit this field. For instructions on creating custom user attributes, please refer to the following article. |
| Account status | Setting for the user's account status |
Displayed only on the user information edit screen.
|
| Password setup | Whether to set an initial password |
*Displayed only when creating a new user.
|
| Initial password | Password the user will use for their first login | Displayed only when creating a new user. |
| Password expiration | Password expiration for the user |
|
| Self Password Reset | Setting for the email address used for self password reset |
If the Self Password Reset feature is enabled, set the email address for self password reset. For an overview of the Self Password Reset feature, please refer to the following article. |
| Role | Setting for permissions to access the Access Control Administration | You can select from the following. *All administrators have view permissions for all pages and can download log files (CSV). For details on roles, please refer to the following article. [Access Control] What can users do by role? |
| Force Logout | Force this user to log out from Access Control | *This does not log the user out from services integrated with Single Sign-On. |
| OTP type | Setting for OTP type |
Displayed only on the user information edit screen. You can select from HENNGE Lock or Email.
|
| OTP emergency token | Issuance of an OTP emergency token | – |
| Access Policy Groups | Specify the Access Policy Groups to which the user belongs | Selecting [View policy group details] allows you to view the configuration details of the Access Policy Groups assigned to the user. For instructions on creating Access Policy Groups, please refer to the following article. Create a New Access Policy Group |
| Allowed services | Specify whether this user is allowed to use services configured for Single Sign-On in [Connected Services] | You can also specify whether to display links to services configured in [Connected Services] in the user's Access Control user portal. |
| Device Certificates | View information on device certificates issued to the user being viewed (Not Downloaded / Downloaded / In Use / Expiring Soon) | Clicking a device certificate column will take you to the certificate edit screen for the selected device certificate. *Displayed only on the user information edit screen. |