Activate or deactivate a user
This article explains how to deactivate a user so they can no longer sign in, and how to reactivate them later. Deactivation is the safe way to remove access without deleting an account and its history.
Before you start
Activating and deactivating users requires the users:manage permission, held by the SystemAdmin role and by any custom role that grants it. The same scope rules that govern editing apply here: a SystemAdmin may act on any account, while a non-SystemAdmin can never act on a SystemAdmin account and may only manage users in a tenant where they hold users:manage.
What deactivation does
Deactivating a user sets the account to inactive, which prevents that person from logging in. The account, its profile, and its role assignments are preserved, so you can restore access at any time by reactivating. Use deactivation when someone leaves, goes on extended leave, or should temporarily lose access.
Note: Deactivation blocks sign-in but does not remove the user's roles. When you reactivate the account, the person regains the same roles and permissions they had before.
Deactivate a user
- Open the user administration area and locate the account.
- Choose to deactivate the user.
- Confirm. The account is marked inactive immediately and the next sign-in attempt is refused.
If the account is already inactive, the action reports that the user is already inactive and nothing changes.
Reactivate a user
- Find the inactive account in the user administration area.
- Choose to activate the user.
- Confirm. The person can sign in again with their existing credentials.
If the account is already active, the action reports that the user is already active.
Deactivation versus password reset
These are different tools for different situations:
| Situation | Use |
|---|---|
| Person should lose access entirely | Deactivate the account. |
| Person is locked out or forgot their password | Admin password reset — this sets a new password and also clears any lockout and failed-login count. |
Tip: If a user is blocked by repeated failed sign-ins rather than by deactivation, an administrator password reset clears the lockout as well as setting the new password, so there is no separate "unlock" step.
Warning: Deactivating an account does not free up a licence seat by itself only if your licence counts total users; if you hit a user limit when creating accounts, deactivating unused users is the usual way to make room, but confirm your licence terms with your administrator.
Related
- Create a user account
- Edit a user's details
- Assign and remove user roles
- Troubleshooting "Access Denied" errors