Background
CyberQP automatically assigns imported accounts to "Sections" based on detected user type (End User, Administrator, or Service).
In some environments, account attributes may result in an account being placed in a different "Section" than intended. This can occur due to variations in source system configuration or how account roles are defined upstream.
With this release, administrators can now move accounts between "Sections" directly, eliminating the need to remove and re-import accounts when adjustments are required.
Prerequisites
- Technician must have access to the Customer
- Technician must have access to the Dashboard Sections for both the "from" and "to"
- Technician must have higher role than HelpDesk (we assume Helpdesk Role is to use the functions, not manage the customer configuration)
Disclaimer
NOTE: Moving an account to a different Section treats the account as a manual import. After the move, technicians must re-associate the account with the PSA, configure Password Storage, and re-enable Rotation when applicable (Administrator or Service Sections). Vault customers will retain historical passwords during the move.
A pop up warning will remind the technician to perform that action.
The following table defines the supported and unsupported account move paths between Sections.
| Origin | Account Source | Destination Results | ||
|---|---|---|---|---|
| End User | Administrator | Service | ||
| End User | Active Directory | - | Possible | Possible |
| End User | Entra/M365 | - | Possible | Not Possible |
| End User | Local | - | Possible | Possible |
| End User | Active Directory with Entra/M365 | - | Possible Split into 2 Entries |
Only the AD Account M365 Account will stay |
| Administrator | Active Directory | Possible | - | Possible |
| Administrator | Entra/M365 | Possible | - | Not Possible |
| Administrator | Local | Possible | - | Possible |
| Service | Active Directory | Possible | Possible | - |
| Service | Local | Possible | Possible | - |
Specific Cases for Moving from/To Sections
- When an End User that is imported with the Active Directory Account and Entra/M365 (Sync enabled) is moved to Administrators section
- The Accounts will be split into separate accounts -
- This will ensure that each account is rotated individually - passwords will be different for each account.
- The Accounts will be split into separate accounts -
- When an End User that is imported with the Active Directory Account and Entra/M365 (Sync enabled) is moved to Services section
- The Active Directory Account will be moved to the Services section. The M365 Account will remain in the End User section
- Because Services are meant for Local or Active Directory only, the M365 Account cannot be moved to Services.
- Because Services are meant for Local or Active Directory only, the M365 Account cannot be moved to Services.
- The Active Directory Account will be moved to the Services section. The M365 Account will remain in the End User section
Process
For each section, as listed above, the ability to move the accounts via the "Change Account Type" menu option will be shown.
You can do this in bulk if you have multiple accounts to move or via the 3 Dot Menu on the far right side of the screen.
- Select the Account(s) you wish to move.
-
Select the Change Account type - and slide out selection
- Select the section you want the account to be moved to.
-
After selecting the section a pop up warning will be displayed. The content of that pop up will vary slightly depending on the account source and destination you selected.
- Reminder - this should be read by the technician to ensure they know what will happen to the account.
- Click Change to complete the Process.
-
A banner will appear at the top of the page to confirm the move was completed.
- If the account was NOT moved, you will see a failure banner.
Next Steps
- Depending on the source of the account, the original section, and the destination section, the Technician will want to ensure they perform any "Matching" to the PSA, Password Storage, Enable Rotation or Self-Serve, etc. functions are completed in order to have the account fully functional as the new account type Section.
Password Storage for any Account Section
IT Glue Matching - Administrator, Service, and End User Accounts – CyberQP
Hudu Matching - Administrator, Service, and End User Accounts – CyberQP
Enable Rotation for Administrator and Service Section
How to Setup Scheduled Password Rotation of Service Accounts with External Password Vault – CyberQP
How to Setup Scheduled Password Rotation of Administrator Accounts with External Password Vault – CyberQP
Matching End Users to the PSA
Match ConnectWise Contacts with CyberQP Accounts – CyberQP
Match Kaseya (Datto) AutoTask PSA Contacts with CyberQP Accounts – CyberQP
Match CyberQP End-User with HaloPSA End-User – CyberQP
Comments
0 comments
Please sign in to leave a comment.