There are basically three types of user accounts in OneSpan Authentication Server:
Regular users. Regular user accounts are intended for individual users. They allow users to authenticate and perform transaction data signing operations using an authenticator.
Administrative users. A user account is considered an administrator account if it has at least one administrative privilege assigned. Administrator accounts are intended solely to perform administrative operations. As a best practice, use a regular user account for authentication and transaction data signing, and a separate, dedicated administrator account for administrative tasks.
Service users. Service users are a specialized type of administrative account. Unlike standard administrative users, they cannot log on interactively to administrative user interfaces, but are designed to automate administration tasks.
The lifecycle of a user account typically consists of three distinct phases: onboarding, active use/management, and offboarding.
Onboarding. During onboarding, new user accounts are created. This includes assigning required user attributes such as identity information, as well as provisioning authenticator devices. For administrative accounts, appropriate administrative privileges or predefined administrator roles are assigned.
Active usage/management. After the initial onboarding, user accounts enter the active usage and management phase. User accounts are used for daily operations, such as authentication and transaction data signing. They may receive updates to reflect organizational changes (such as department or role changes), personal updates (such as name or contact details), or security-related adjustments (such as password resets, role modifications, or access reviews).
Offboarding. User accounts are deactivated when they are no longer needed, for example, due to employees leaving the organization or the end of contractual engagements. Offboarding actions may include disabling the account to prevent further access, revoking permissions, and optionally deleting the account entirely.
Whether a OneSpan Authentication Server user account can actively be used for its allowed operations depends on several status flags that determine the overall account status:
Account status. This indicates whether the user account is enabled and permitted to authenticate.
A disabled user account can only be enabled by an administrator.
Lock status. This indicates whether the user account is locked. A user account can be locked automatically after a defined number of unsuccessful authentication attempts or manually by an administrator.
A locked user account can be unlocked using various methods.
Expiration status. This indicates whether the user account has expired. A specific expiration date can be defined, after which the user account cannot longer be used for authentication. This is typically used for temporary users, such as contractors or external auditors.
An expired user account can only be reset by an administrator.
Activity status. This indicates whether the user account has been suspended due to inactivity. A user account may be suspended due to inactivity if it has not been used for a defined period.
A suspended user account can only be reactivated by an administrator.