Transferring users is a significant step in configuring your Metric Insights instance. Metric Insights offers a range of tools to help ensure the process is smooth and reliable.
Please refer to this article to explore the recommended User onboarding functionalities.
In this article:
Prerequisites
Before beginning the transfer process, it's best to prepare all the key components in advance. You'll need to:
- Identify the users who require accounts in Metric Insights and determine their User Types according to Metric Insights standards.
- Determine what Groups you'll need. In Metric Insights, the Group a user belongs to defines their content access rights, so it's important to plan your Group list beforehand.
Create Groups of Users
Organizing users into Groups significantly streamlines content access management. All access rights granted to a Group are directly inherited by its members. By managing access at the Group level, you can control what all users within that Group are permitted to do in Metric Insights, and tailor the security model to your organization's requirements.
There are two main ways to manage Groups in MI. Determine which approach best suits your needs:
- Create a custom Group in Active Directory or use the Group created in another identity management platform, sync it with MI, and assign the required access rights (Privileges or Privilege Sets).
- While using this approach, you can manage all the users in one tool, without needing to repeat the same actions on different platforms.
- Create a custom Group directly in Metric Insights and assign the required Privileges or Privilege Sets.
Bring Groups and Users
Metric Insights provides the functionality to create Users manually; however, in most cases, this approach requires a significant amount of time and effort. Therefore, we recommend using one of the following two methods:
- Synchronize existing Groups and Users. This approach ensures that all User accounts created within a user management tool are automatically created in the Metric Insights instance and assigned to the appropriate Groups.
- First Sign-On Authentication. With this method, User accounts are created automatically at the moment the User logs in.
Sync Existing Groups and Users
If a User Group already exists in Active Directory or another identity management platform, synchronizing it with Metric Insights is significantly more efficient than creating user accounts manually. After synchronization, all specified Groups and Users that exist in the user management tool will be created in the MI instance. Metric Insights uses a specialized script for it. The synchronization process operates as follows:
- The script adds external Groups to Metric Insights, along with their assigned Users, while preserving the exact Group naming convention.
- If a User in a Group being synced does not yet exist in Metric Insights, the User is automatically created in MI as needed.
- Unless otherwise specified via the --user-type parameter, the User is created as a Regular User with no assigned access rights (Privileges or Permissions). Only informational profile data is included, along with the User's assigned Group: User ID, email address, first name, and last name.
Groups and Users can be synced using:
- Okta SAML via 'mi-okta-usersync' Script;
- Office 365 Groups via 'mi-o365-usersync' Script;
- LDAP/AD via 'mi-ldap-usersync' Script;
- SCIM via Microsoft Entra;
- SCIM is the recommended approach for user onboarding. It reduces MI's burden for maintaining sync configuration.
First Sign-On Authentication
Metric Insights provides a feature that enables User account creation upon first successful login. Once you configure the authentication method, Users will be able to log into the Metric Insights instance using the same credentials they use for other tools within your organization.
Metric Insights supports the following authentication methods:
Moving Users Between Groups
If necessary, Users can be moved from one Group to another. If there's a significant number of Users that need to be moved between Groups within a Metric Insights instance, best practice is to perform this in bulk. For a detailed guide, please refer to the Moving Users Between Groups in Bulk article.
Check User Access
Once all the necessary User accounts are created, confirm that they have all the required content access rights.
For more details on content onboarding, check the Content Onboarding Best Practices article. For more details on granting access to Users, check the Security Model Best Practices article.