Skip to main content

Manage user accounts with Access Identity enabled

How creating users, managing passwords, and setting roles works in Core+ when Access Identity is enabled, with or without federated single sign-on (SSO).

Written by Erica

When Access Identity is enabled for your Core+ site, some parts of user account management work differently. You still create users and set roles in Core+, but how a user signs in — and where their password is managed — depends on the email address on their account and whether your organisation has configured federated SSO. Setting up Access Identity and federated SSO is handled separately from Core+.

Terms used in this article

  • Access Identity: The Access Group's identity management and sign-in service. Users sign in once with a single set of credentials to access multiple Access products and connected third-party applications.

  • Federated identity provider: Your organisation's own identity system (for example, Microsoft Entra or Google Workspace) that holds your users' accounts and verifies their credentials. When configured with Access Identity, users sign in with their existing company credentials.

  • Federated SSO: Single sign-on where Access Identity delegates credential checks to your federated identity provider, rather than to a password stored in Access Identity.

  • Linked account: A Core+ user account whose email address matches an account in Access Identity (and your federated identity provider, where configured). The email address is what links the accounts.


Create a user

⚠️ Important: A user existing in Access Identity or your federated identity provider does not automatically create a Core+ account. You must still create the user in Core+.

Create the user record in Core+ as normal. The email address you enter determines how the user signs in:

  • Staff in your organisation: Enter the user's company email address in the Email field. This links the Core+ account to Access Identity and, where configured, to your federated identity provider. You must still set a username and password during creation, but these are largely redundant — the user signs in with their usual SSO credentials. The email address is what links the account.

  • External users: The user must first register for an Access Identity account at https://identity.accessacloud.com/auth/signin. Enter the same email address they registered with in the Email field on their Core+ account so the accounts link.


Manage passwords

Where the user manages their password depends on whether their account uses federated SSO:

  • Federated SSO enabled: Password management is controlled by your organisation's internal policies. Users who forget their password follow your internal reset process — the Core+ and Access Identity passwords are not used.

  • Federated SSO not enabled (Access Identity only): Users reset or change their password directly in Access Identity.


Set a role

Roles are assigned to the user account in Core+ as normal. Access Identity and federated SSO do not affect roles — they are managed entirely within Core+.


Implementation

During implementation, additional steps may apply depending on how your organisation's Access Identity and federated SSO have been configured. Contact your implementation consultant for details.

Did this answer your question?