Manage Mojo Launchpad Users

Mojo Launchpad lets you create users and assign permissions to them on various Mojo Launchpad services in the cloud, including Mojo Launchpad. Each user is assigned a profile defining permissions granted to the user to perform various actions in the respective Mojo Launchpad services.

 

A profile is a canned set of permissions that defines the actions a user can perform in the context of Mojo Launchpad. The primary objects in Mojo Launchpad are as follows.

 

Profiles

Mojo Launchpad provides the following system-defined profiles.

 

 

 

 

The following table explains the privileges on Mojo Launchpad services for a new user based on the profile assigned to the user.

 

Profile

Role/Privileges in Mojo Launchpad Services

Mojo Launchpad Mojo Wireless Manager Mojo Guest Manager Mojo Packets
Super Admin User Management, Settings, Device Registration, Customer Management Superuser/Poweruser Administrator User
Global Customer Admin  Customer Management -- -- --
Admin User Management, Settings, Device Registration Superuser/Poweruser Administrator

User

Custom Privileges must be explicitly set for the user. The role must be explicitly configured when the service is turned on.

 

Users can be either an MSP user and a non-MSP user. MSP users have customer management privileges. The privileges for a user depends on the profile assigned to him.

 

You must have User Management privileges in Mojo Launchpad to add, edit, delete user, that is, user account information.

The changes that a user can make to another user or a key depend on the profile of the logged in user and that of the user or key being edited. The following table details the actions that can be performed by a logged in user on another user/key.

Profile of User Editing Another User

Profile of User/Key Being Edited

Super Admin

Global Customer Admin

Admin

Custom

Super Admin

Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Reset key value.

Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Change permissions on services.

Reset key value.

Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Change permission on customer accounts.

Reset key value.

Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Change permissions on services or customer accounts.

Reset key value.

Global Customer Admin

 -- Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Change permissions on common services.

Reset key value.

Edit account information/key name.

Lock user/key.

Change permissions on customer accounts.

Reset key value.

Edit account information/key name.

Change profile.

Lock user/key.

Delete user/key.

Change permissions on common services and customer accounts.

Reset key value.

Admin

--

Edit account information/key name.

Lock user/key.

Change permissions on own services.

Reset key value.

Edit account information/key name.

Change profile.
Lock user/key.
Delete user/key.
Change permissions on common customer accounts.
Reset key value.

Edit account information/key name.

Change profile.
Lock user/key.
Delete user/key.
Change permissions on services and common customer accounts.
Reset key value.
Custom

--

--

--

Edit account information/key name.

Change profile.
Lock user/key.
Delete user/key.
Change permissions on common services and common customer accounts.
Reset key value.

Note: To edit permissions on common customer accounts, a user must have customer admin privileges on all customer accounts assigned to the user/key being edited.

 

Apart from the system-defined profiles described above, Mojo Launchpad facilitates the creation of user-defined profiles. For more information on user-defined profiles, refer to Manage User-defined Profiles.

Users can be categorized based on the mode of authentication. Local users are users that are authenticated locally in Mojo Launchpad. Federated users are users that authenticate using third-party identity providers to log in to Mojo Launchpad services through Mojo Launchpad.

Add User

 When you add a user, you first define the account information for the user. The user is assigned the Custom profile, by default. After saving the user account information, you must explicitly assign service privileges to the user.

There are two types of users, local users and federated users.

Mojo Launchpad authenticates a local user by means of a user-name password combination. A local user can be authenticated with two-factor authentication if two-factor authentication has been enabled for the customer to which the user belongs. Refer to Manage Two-Factor Authentication for details on enabling two-factor authentication.

A user that is authenticated by a third-party identity provider is called a federated user.

All users are local users when federated authentication is not available to your organization. If federated authentication has been activated and enabled for your organization, you must select a user type when you add a user.

A federated user is added automatically when he or she authenticates successfully with the third-party identity provider and signs in to Mojo Launchpad. If there is a change in the user details from the federated identity provider, the record for this user in Mojo Launchpad is overwritten when the user signs in. If the details of a federated user are modified in Mojo Launchpad, the changes coming from the federated identity provider are ignored. You can choose to override this behavior and overwrite a modified federated user record with the changes coming from the federated identity provider.

To add user account information, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.
  2. Click Admin and then click the Users tab.
    A list of existing users appears.
  3. Click New User to add a new user.
  4. Enter the account information.

 

Field

Description

Login Id

Login Id for the user.

Note: The Login Id must be in the email format only.

Email

Email Id of the user.

Note: The Login Id and Email need not be the same.

First Name

First name of the user.

Last Name

Last name of the user.

Time zone

Time zone of the user.

User Type

The type of user. Select local if this user authenticates using Mojo Launchpad. Select Federated if this user authenticates using federated authentication with a third-party identity provider. This field is available only when federated authentication is activated and enabled for your organization.

Reset to Federated Profile

Select the check box to overwrite the user details for a federated profile with the changes coming from the federated identity provider. This check box is available only when federated authentication is activated and the profile for the federated user has been modified.

2-Factor Authentication

Select the check box to enable two-factor authentication for the local user. This check box is visible only when two-factor authentication is enabled for the customer and the logged in user is Admin or Super Admin.

Note: The two-factor authentication check box is selected, by default, when two-factor authentication has been enforced for the customer to which the user belongs.

   

  1. Click Save.

 

When a new user is added, a welcome email is sent to the user to set a password for his account. The user can click the link provided in this e-mail and set his password.

Note: The welcome email will be sent to the email Id mentioned in the Email field.

Assign Profile

Once a user has been added, you must assign a profile to him.

To assign profile to a user, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.
  2. Click Admin and then click the Users tab.
    A list of existing users appears.
  3. Right-click the required user row and click the Service Privileges option on the pop-up menu. Alternatively, you can click the user row and then click the Service Privileges tab.
    The Service Privileges screen appears.
  4. Select the required profile.
  5. Click Save.

Refer to the Manage Service Privileges for User section to know more about assigning service privileges to a user.

Note: If any changes are made to the profile assigned to a federated user in Mojo Launchpad, the changes coming from the federated identity provider are ignored. If you want reset this default behavior, you must select the Reset to Federated Profile check box on the Edit User page.

Change Profile

The following table details the changes in the privileges of a user when the profile is modified while editing the service privileges for a user.

 

Old Profile

   

New Profile

 

Super Admin

Admin

Global Customer Admin

Custom

Super Admin

--

Customer management permissions are retained.

Permissions on own services are retained.

All previous permissions are retained until you define new rules.

Admin

Highest permissions on Mojo Launchpad and all services assigned  No permission can be customized.

--

Permissions on own services are retained.

All previous permissions are retained until you define new rules.

Global Customer Admin

Highest permissions on Mojo Launchpad and all services assigned  No permission can be customized.

Customer management permissions are retained.

--

All previous permissions are retained until you define new rules.

Custom

Highest permissions on Mojo Launchpad and all services assigned. No permission can be customized.

Highest privileges on all services. Customer management can be customized.

Highest privileges on all customers. Service management can be customized.

--

Edit User

To edit user account information, you must have user management privileges.

 

You cannot edit the login ID of a user. All other fields are editable. If you edit the e-mail id of a user, a notification e-mail is sent to the old e-mail ID, and a confirmation e-mail is sent to the user's modified e-mail ID. The purpose of the confirmation e-mail is to seek confirmation for the modified e-mail ID. The user can confirm the modified e-mail ID by clicking the link provided in the confirmation e-mail.

 

Note: If you change an e-mail ID multiple times before it is confirmed by the user, the confirmation e-mail that has been sent to latest e-mail ID is considered valid. Even if the user clicks the links provided in the confirmation e-mail to an intermediate e-mail ID, it is ignored by Mojo Launchpad.

 

If the user has not received the confirmation e-mail, you can resend the e-mail to the modified e-mail ID by clicking the Resend email link seen below the Email field on the Edit user page. This link is visible only if the user has not confirmed the modified e-mail ID by clicking the link provided in the confirmation e-mail.

If you change the profile of a federated user, the profile provided by the federated identity provider is ignored. You can reset this behavior and accept the profile provided by the federated identity provider.

 

To edit user account information, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.

  2. Click Admin and then click the Users tab. A list of existing users appears.

  3. Click the user row to edit.

  4. Modify the account information.

 

Field

Description

Email

E-mail ID of the user to which e-mails can be sent. This field cannot be edited if the user is a federated user.

First Name

First name of the user. This field cannot be edited if the user is a federated user.

Last Name

Last name of the user.

Time zone

Time zone of the user.

User Type

Select the user type. This field is visible only if federated login is activated and enabled for your organization. When federated login is activated and enabled, two types of users are available-local and federated.

Reset Password

Select the check box to reset the user's password. This field is visible only if the user is a local user.

Reset to Federated Profile

Select this check box to accept the profile provided by the federated identity provider if the profile has been edited for the federated user in Mojo Launchpad.

2-Factor Authentication

Select the check box to enable two-factor authentication for the local user.  This check box is visible only when two-factor authentication is enabled for the customer and the logged in user is Admin or Super Admin..

Note: The two-factor authentication check box is selected, by default, when two-factor authentication has been enforced for the customer to which the user belongs.

 

  1. Click Save.

Changes to user account information reflect on subsequent login, that is, when the user logs out of and in to Mojo Launchpad.

Change Authentication Mode for User

A local user is a user that authenticates to Mojo Launchpad using Mojo Launchpad credentials. A federated user is a user that authenticates to Mojo Launchpad using his federated login credentials. It is possible to change the mode of authentication of a user at any time. Thus, a local user can become a federated user and vice versa.  

When a local user becomes a federated user, he or she is unable to use his Mojo Launchpad password to log in to Mojo Launchpad.

Lock/Unlock User

You might want to define users and keep them ready for use, but provide them access to Mojo Launchpad at a later point. Or, you might want to restrict access to Mojo Launchpad for users that are already active. You might also want to block some users instead of deleting them. In such cases, you can lock the users account to prevent them from accessing Mojo Launchpad.

You can unlock locked users at any time. When you lock a user, a padlock icon appears for this user indicating that the user account is locked.

 

To lock or unlock a user, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.

  2. Click Admin and then click the Users tab.
    A list of existing users appears.

  3. Right-click the user row you wish to lock or unlock.

  4. Click the Lock/Unlock option on the pop-up menu.

Reset Password

You cannot modify the password for another user. However, you can reset a user's password if you have user management privileges.

 

When you reset a user's password, an e-mail is sent to the user to set a new password for his account. The user can click the link provided in the notification e-mail and set his new password.

 

To reset the password for a user, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.

  2. Click Admin and then click the Users tab. A list of existing users appears.

  3. Click the user row for the user whose password is to be reset.

  4. Select the Reset Password check box to reset the user account.

  5. Click Save.

 

An e-mail to set a new password is sent to the user's e-mail ID.

Search User

You can search for users based on login ID, name, email, last login or profile.

To search a user, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.

  2. Click Admin and then click the Users tab.

  3. Type the search keyword in the search users box at the top-right side.

A list of matching users appears as you type in the search keyword.

Delete User

You can delete both local users and federated users. When you delete a federated user, the record created for the federated user in Mojo Launchpad gets deleted. When the federated user logs in to Mojo Launchpad the next time, a fresh record for this user is created in Mojo Launchpad.

To delete user account information, perform the following steps.

  1. Log on to the Mojo Launchpad using your credentials.

  2. Click Admin and then click the Users tab. A list of existing users appears.

  3. Right-click the user row to delete.

  4. Click the Delete option from the pop-up menu that appears.
    A message prompting you to confirm the deletion appears.

  5. Click Yes to permanently delete the user.

Note: If any problem occurs when deleting service-related data for the user in Mojo Launchpad, the user does not get deleted.

User Account Suspension Policy

In the Suspension Policy section under Admin>Settings, you can configure the duration for which a Mojo Launchpad user account must be suspended on consecutive login failures.

 

To configure this option, you must provide the following information:

 

Option

Description

Maximum failed login attempts

Number of consecutive failed login attempts.

Lockout period (in mins)

Time duration in minutes during which the consecutive failed login attempts must occur to activate the policy.

Locked out message

The message to be displayed if consecutive user login failure occurs and account is suspended.

Minimum password length

The minimum number of characters required to set the password.

2-Factor Authentication

To authenticate with two different credentials. Refer Manage 2-Factor Authentication for more information.

Force 2-Factor Authentication

To enforce 2-Factor authentication. Refer Enforce 2-Factor Authentication for more information.