Manage Fudo ShareAccess Members

Inviting Members

You can invite users to access organization resources via Fudo ShareAccess or to become an organization members.


Inviting a user establishes a connection between Fudo Enterprise user and Fudo ShareAccess user, which is necessary to grant access to resources.

Note

  • You can manage Fudo ShareAccess users directly from within the Fudo ShareAccess or the Fudo Enterprise.

  • If you are using Fudo Enterprise, inviting users through it is more convenient for management purposes. Users invited directly via Fudo ShareAccess 1.0 will not be created in Fudo Enterprise.

Note

Starting with version 6.1.2, users imported from an Active Directory or LDAP service can also be invited to Fudo ShareAccess and granted the Trusted status. The Fudo ShareAccess identity is stored as a separate ShareAccess Key authentication method, so it is no longer overwritten by directory synchronization and no longer conflicts with the Synchronize with LDAP option. For more information, refer to the Users Synchronization - User Directory section.

To add users from Fudo Enterprise and connect them with Fudo ShareAccess follow below steps:

  1. Create user with email that will be used as email for Fudo ShareAccess access:

    • Select User Management > Users and then click Add user.

    • Enter user name.

    • From the Role drop-down list select desired role.

    • In the User Data tab, in the User info field enter:

      • user’s full name (required),

      • user’s email address that will be used as email for Fudo ShareAccess access (required),

      • user’s organizational unit,

      • user’s phone number.

    • Click Save.

    • Go back to the Settings tab, and in the Authentication section select desired authentication type from the Add authentication method drop-down list. This will be used to authenticate user against Fudo Enterprise Access Gateway.

    • Click Save and close.

  1. Select Settings > Fudo ShareAccess and click the Invite button.

  1. In the modal window select users you want to invite from the list of available users.

Note

  • Only users with a configured email address can be invited to Fudo ShareAccess.

  • The email address is recorded at the moment of invitation as the user’s Fudo ShareAccess user name and is not changed afterwards. Editing the user’s email address in Fudo Enterprise (manually or through directory synchronization) does not affect the existing Fudo ShareAccess membership. This is why the Email column on the Fudo ShareAccess list can differ from the email address shown on the user’s form.

  • A given Fudo ShareAccess user name can be assigned to only one Fudo Enterprise user.

  1. Fudo ShareAccess requires a user to be Trusted in order to access assigned resources:

    • Click the Invite and Trust button to trust the user immediately without verification, or

    • Click the Trust button to verify the user after they accept the invitation.

Note

Inviting users with the Trust option will result in the immediate, unattended sharing of resources.

  1. Sending an invitation will add entries to the users list, with their status marked as Pending until the user clicks the email link to join the organization.

Note

Sending an invitation means the user will receive an email containing a link that allows them to either create an account and accept the invitation or simply accept the invitation if they already have an account on Fudo ShareAccess.

Verifying Members Status

User that is paired with Fudo ShareAccess can have Trusted or Untrusted status. This status defines if user can see resources in Fudo ShareAccess.

Note

The Fudo Enterprise user with a role that has permissions to manage Fudo ShareAccess can perform verification (change Untrusted status) only after the user has created an account in Fudo ShareAccess and accepted the invitation to join organization.

  1. Select Settings > Fudo ShareAccess.

  2. Select users from the list and click the Trust button.

../../_images/5_5_shareaccess_trust.png
  1. Ask user to provide the Fingerprint Key from his Fudo ShareAccess account and compare it with the fingerprint displayed in the modal window.

../../_images/5_5_shareaccess_fingerprint.png

Note

The Fingerprint Key can be viewed after logging into the Fudo ShareAccess user account, selecting Settings from the drop-down menu in the upper-right corner and then Security in the left-hand menu.

../../_images/1_0_fingerprint.png
  1. Click Confirm. After confirmation user is trusted.

Note

  • There is no requirement to complete that process. It is at the Administrator’s discretion whether to trust users without verification.

  • Blocking the user in Fudo Enterprise will automatically disable their access to resources shared with Fudo ShareAccess.

  • An administrator can also revoke a previously granted trust without disconnecting the user from Fudo ShareAccess. The Untrust action is available on the user’s form, in the ShareAccess Key authentication method. For more information, refer to the ShareAccess Key Authentication Method section.

ShareAccess Key Authentication Method

The Fudo ShareAccess identity of a user is presented on the user’s form as a separate authentication method named ShareAccess Key. This lets the administrator inspect the Fudo ShareAccess membership and manage it without leaving the Users tab.

Note

  • The ShareAccess Key method appears automatically after the user has been invited to Fudo ShareAccess and disappears when their access is revoked. It cannot be added manually and is therefore not available on the Add authentication method drop-down list.

  • The ShareAccess Key method is not used to log in to Fudo Enterprise and is not taken into account in the order of authentication methods. Fudo ShareAccess uses it to verify the signature of the requests sent by the user.

To review a user’s Fudo ShareAccess identity, proceed as follows.

  1. Select User Management > Users and select the user from the list.

  2. Go to the Settings tab and find the ShareAccess Key entry in the Authentication section, in the Methods field.

The entry displays the following information:

  • Username - the user’s Fudo ShareAccess user name, recorded at the moment of invitation.

  • Fingerprint - the SHA256 fingerprint of the user’s Fudo ShareAccess key pair. The fingerprint is displayed only after the user has accepted the invitation and their keys have been transferred to Fudo Enterprise.

The following actions are available, depending on the state of the Fudo ShareAccess membership:

Action

Availability

Result

Trust

the user has accepted the invitation and is not trusted yet

Opens the fingerprint comparison window and grants the Trusted status. The user gains access to the resources shared with them.

Untrust

the user has the Trusted status

Revokes the Trusted status. The user remains a member of the organization but loses access to the shared resources until trust is granted again.

Delete

always

Ends the Fudo ShareAccess membership of the user. It is the equivalent of the Revoke access action available on the Fudo ShareAccess list.

Note

Before the user accepts the invitation, only the Delete action is available - there are no keys to verify yet, so trust cannot be granted.

Creating an Account Without an Invitation

It is possible for user to create an account without an invitation. If the user’s email domain matches an existing organization’s domain in Fudo ShareAccess, they will automatically be assigned to that organization. By default, the account will be inactive, and the user will not have access to Fudo ShareAccess. The organization owner will receive an email notification about the new user, including a link to activate the user’s account.

For more information please follow the ShareAccess documentation.


Revoking Members Status

The administrator has the ability to revoke access to Fudo ShareAccess. This means the user will be disconnected from their Fudo ShareAccess account and will no longer be able to work with Fudo ShareAccess. To carry out this procedure:

  1. Select Settings > Fudo ShareAccess.

  2. Select the users you wish to disconnect and click Revoke Access.

  3. Upon confirmation, these users will be removed from the list.

../../_images/5_5_shareaccess_revoke.png

Note

Access can also be revoked from the user’s form by deleting the ShareAccess Key authentication method. The result is the same as using the Revoke access action. For more information, refer to the ShareAccess Key Authentication Method section.

Deleting Members

There is no possibility to remove user from Organization or Fudo ShareAccess. The only possibility is to set account as Inactive. For more information please follow the ShareAccess documentation.


Related topics: