Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / For administrators

Users and roles

Manage > Users lists everyone in your organization who can sign in or receive a quarantine: synced mailbox users and your organization administrators.

Roles

RoleCan do
UserTheir own quarantine, recent mail, personal allow and block lists and account security, in the user portal. No admin console.
Organization administratorThe admin console for your organization. Administrators also have their own quarantine and lists under My mail.

Platform settings, service health and API tokens are run by Larström Technologies and are not part of your console.

Finding users

Search by address or name, and filter by role. The list shows VIP and disabled badges, the number of aliases, the sign-in method (local, m365, google, ldap, "+ MFA" when two-factor is on) and the last sign-in.

Add user

Mailbox users normally arrive through user sync rather than being added by hand. To add someone yourself, use Add user:

FieldMeaning
EmailSign-in name and primary address.
NameDisplay name. It matters for VIP protection.
RoleUser - own quarantine or Organization administrator.
Password (optional)At least 12 characters. Leave it blank for people who sign in with Microsoft or Google, with their Windows password (Exchange), or with emailed sign-in links.

Click Create.

Editing a user

Click a user to open their page. Their messages opens Message trace for their mail.

FieldMeaning
Display nameShown in the console and used for impersonation checks.
RoleYou cannot change your own role.
AliasesOther addresses delivered to this mailbox, comma separated. Mail to an alias shows in this user's quarantine and counts for recipient checks. User sync fills these in from your directory.
ActiveInactive users cannot sign in and get no digests. You cannot deactivate yourself.
VIP (executive impersonation protection)See VIP users.
Send quarantine digestsWhether this person receives quarantine digests. Users can change this themselves too.
Set new passwordResets the password. The user's existing sessions end.
Reset two-factor (user re-enrolls)Shown when two-factor is on. Removes their authenticator so they can set it up again, for example after losing a phone.

Save applies the changes and also clears a lockout after repeated failed sign-ins. Every change is written to the audit log.

The Personal allow & block entries card lists the user's own list entries; Remove deletes one.

VIP users

Mark executives, finance and HR approvers as VIP. Outside mail that uses a VIP's display name gets the rule VIP_DISPLAY_NAME (+6 points) and is always shown to the AI model (unless a policy turns that off). This is the most common business email compromise trick: a stranger's address with your CEO's name.

Two-factor sign-in

Every user can turn on two-factor sign-in with an authenticator app under Account & security; see User portal. We recommend it for every administrator. For people who sign in with Continue with Microsoft or Continue with Google, enforce two-factor in Microsoft Entra ID or Google Workspace.

After several wrong passwords in a row, an account is locked for a few minutes. Saving the user's record unlocks it at once.