# Overview

Use **Admin &gt; Users** to create and maintain MiRTA PBX web administrator and operator accounts. These accounts control access to the administration interface; they are separate from SIP extensions and extension web-panel accounts.

The page is available to users with the **Has menu Admin/Users** privilege. The records and selectable values shown to an administrator are further limited by tenant, reserved-profile, routing-profile, call-rate, and user-profile privileges.

<figure id="bkmrk-admin-users-page-wit">![Admin Users page with fictional documentation accounts.](https://manual.mirtapbx.com/uploads/images/gallery/2026-08/users-overview.png)<figcaption>Admin Users page with fictional documentation accounts.</figcaption></figure>*The screenshot was captured from the current MiRTA PBX server. The displayed users and tenant are fictional documentation values inserted only in the browser; no PBX records were changed.*

## User list

The grid initially shows the account identity, authentication method, assigned profile, and allowed tenants. Select a row before using actions that operate on an existing account.

<table id="bkmrk-columndescription-us"><thead><tr><th>Column</th><th>Description</th></tr></thead><tbody><tr><td>Username</td><td>Unique login name used to access the MiRTA PBX web interface.</td></tr><tr><td>Description</td><td>Administrative description of the account or its owner.</td></tr><tr><td>Authentication</td><td>**Internal** uses the password stored by MiRTA PBX. **LDAP** authenticates the user through the configured LDAP service.</td></tr><tr><td>Profile</td><td>Primary user profile that supplies menus and privileges.</td></tr><tr><td>Tenants</td><td>Tenants the account is allowed to access.</td></tr></tbody></table>

Select **Columns** to show or hide additional account properties, including Email, Profile ID, LDAP settings, IP-filter state, 2FA type, password-expiration state, password lock, dynamic-IP permission, and token validity. The column choice is retained in the current browser.

## List actions

<table id="bkmrk-actionpurpose-addope"><thead><tr><th>Action</th><th>Purpose</th></tr></thead><tbody><tr><td>Add</td><td>Opens **Define User** for a new web account.</td></tr><tr><td>Edit</td><td>Opens the selected account in **Define User**.</td></tr><tr><td>Delete</td><td>Deletes the selected account after confirmation, subject to tenant and reserved-profile privileges.</td></tr><tr><td>Search</td><td>Searches the user list. When advanced filters are enabled, multiple conditions can be combined.</td></tr><tr><td>User Activity</td><td>Opens the user activity log. With a row selected, the log is filtered to that user; without a selection, it shows all accessible activity.</td></tr><tr><td>User Groups</td><td>Opens user-group administration. This action is shown only with the **Can manage the User Groups** privilege.</td></tr><tr><td>Columns</td><td>Opens the column chooser and stores the selection in the browser.</td></tr></tbody></table>

## Which users are visible

<table id="bkmrk-privilegeeffect-can-"><thead><tr><th>Privilege</th><th>Effect</th></tr></thead><tbody><tr><td>Can edit all tenants</td><td>Allows the administrator to view and manage user accounts across all tenants.</td></tr><tr><td>Can edit own tenants</td><td>Limits the list to accounts assigned to at least one tenant also available to the current administrator.</td></tr><tr><td>Can manage reserved profile users</td><td>Allows accounts using reserved user profiles to be displayed and maintained.</td></tr></tbody></table>

## Define User: information and authentication

<table id="bkmrk-field-or-optionpurpo"><thead><tr><th>Field or option</th><th>Purpose</th></tr></thead><tbody><tr><td>Username</td><td>Required unique login name. MiRTA PBX checks that the name is not already in use.</td></tr><tr><td>Description</td><td>Free-form administrative description.</td></tr><tr><td>Email</td><td>Address used for password emails and email-based two-factor authentication.</td></tr><tr><td>Password</td><td>Local password for an internally authenticated account. Leave it empty while editing to keep the existing password. **Generate** creates a suggested password.</td></tr><tr><td>Send Email</td><td>Sends the create/update user email template with the new credentials. A new password and valid email address are required.</td></tr><tr><td>LDAP</td><td>Uses LDAP instead of the local password and disables local password entry.</td></tr><tr><td>Custom LDAP user</td><td>Optional custom LDAP user connection string for this account.</td></tr><tr><td>Never expire</td><td>Exempts the local password from the expiration period configured in Admin Settings.</td></tr><tr><td>Password expiration date</td><td>Shows the calculated expiration date and whether a change is due. It is informational and depends on the global password-expiration setting.</td></tr><tr><td>Force password change at login</td><td>Requires the user to replace the local password at the next login.</td></tr><tr><td>Lock password, user cannot change it</td><td>Prevents the account holder from changing the password.</td></tr><tr><td>Last successful login</td><td>Shows the most recent successful login time for an existing account.</td></tr><tr><td>Login status</td><td>Shows whether inactivity housekeeping disabled the account. Select **Re-enable on save** to reactivate it.</td></tr><tr><td>Allow change of IP in the same session</td><td>Allows an authenticated browser session to continue when the client IP address changes. Leave disabled unless mobile or changing networks require it.</td></tr><tr><td>User Profile</td><td>Primary privilege profile that determines the menus and operations available to the user.</td></tr></tbody></table>

Some fields can be shown, hidden, unavailable, prefilled, or locked through **Admin &gt; New Items Defaults**. Administrators with the corresponding override privileges can reveal or edit those fields.

## Resource assignments

<table id="bkmrk-fieldpurpose-tenants"><thead><tr><th>Field</th><th>Purpose</th></tr></thead><tbody><tr><td>Tenants</td><td>Defines which tenant records and tenant-level pages the account can access.</td></tr><tr><td>Allowed Routing Profiles</td><td>Defines which voice, SMS, and fax routing profiles the user can select when maintaining permitted objects.</td></tr><tr><td>Allowed Call Rates</td><td>Defines which client call-rate tables the user can select.</td></tr><tr><td>Allowed User Profiles</td><td>Defines which profiles the user may assign when creating or editing other accounts.</td></tr></tbody></table>

The available choices depend on the privileges of the administrator performing the edit. A tenant-limited administrator cannot grant access to resources that the administrator cannot use.

## Restrictions

Restrictions narrow access inside the assigned tenants. Select only the permitted objects. Leaving a restriction list empty means that the user is not restricted by that list.

<table id="bkmrk-fieldpurpose-restric"><thead><tr><th>Field</th><th>Purpose</th></tr></thead><tbody><tr><td>Restricted to Queues</td><td>Limits queue pages, queue status, and queue-related information to the selected queues.</td></tr><tr><td>Restricted to Extensions</td><td>Limits extension-related pages and information to the selected extensions.</td></tr><tr><td>Restricted to Providers</td><td>Limits provider-related pages and information to the selected providers.</td></tr></tbody></table>

## Additional security

<table id="bkmrk-field-or-optionpurpo-1"><thead><tr><th>Field or option</th><th>Purpose</th></tr></thead><tbody><tr><td>Use IP Filter</td><td>Restricts login to the addresses and IPv4 networks in **Allowed IP list**. Test the list before enabling it for the only administrator account.</td></tr><tr><td>Allowed IP list</td><td>Enter IPv4 addresses or CIDR networks. Whitespace, commas, and semicolons can separate entries; `#` starts a comment. An address without a prefix is treated as a single host.</td></tr><tr><td>Use Two Factors Authentication (2FA)</td><td>Selects no 2FA, a code sent by SMS, a code sent by email, or Google Authenticator.</td></tr><tr><td>Mobile phone number</td><td>Destination used when SMS two-factor authentication is selected.</td></tr><tr><td>Secret code</td><td>Secret used by Google Authenticator. **Get** generates a secret and QR code.</td></tr><tr><td>Autogenerate</td><td>Defers Google Authenticator secret generation and enrollment until login.</td></tr></tbody></table>

## Save, delete, and related actions

- **Save** stores the account and its tenant, routing-profile, call-rate, user-profile, and restriction assignments.
- **Delete** removes the account after confirmation when the current administrator has sufficient scope.
- **Back** returns to the Users list.
- **User Quick shortcuts** opens shortcut configuration for an existing account.

**Security recommendation:** give each administrator an individual account, assign the least-privileged profile and tenant scope required, enable 2FA, and review **User Activity** regularly. Before deleting an account, verify that no operational process still depends on that login.