Previous Topic: Manage User Accounts and PasswordsNext Topic: Password Policies


User Accounts

A user account is a directory entry with a user password. This password must be stored in the attribute userPassword.

You can use CA Directory to manage these user accounts, including locking and unlocking user accounts, setting up password quality rules, and assigning account suspension rules.

You can also create groups and roles in the directory. While roles are usually only useful for managing user entries, you can use groups to manage other kinds of entries as well.

A user account can be in one of the following states:

Active

The user can log in.

Expired

The user cannot log in because they have not changed their password recently.

Suspended

The user cannot log in because they have tried to log in with invalid credentials too many times, or they have not logged in recently.

Locked

The user cannot log in because an administrator has locked the account.