Create users
Create user accounts to provide individuals access to the Veracode Platform and assign roles to their accounts to grant users permissions.
New users receive an activation email with a one-time activation link to activate their Veracode Platform user account. The activation link is valid for seven days.
Prerequisites
- To create and update users, you must have a user account with the Administrator or Team Admin role.
- To delete users, reset passwords, request email verifications, or monitor user activity, you must have a user account with the Administrator role.
Use automated provisioning
You can create users manually, or you can automate user creation with Just-In-Time (JIT) provisioning with SAML, SCIM, and the Identity API. JIT provisioning automatically creates users when they first access the Veracode Platform using SAML and keeps user information synchronized with your identity provider. For large-scale user provisioning, you can use the Identity API to programmatically create and manage users.
Create a user manually
Add a new user account to your organization. You can create users in the Veracode Platform or with the Identity API. You can also create a user by copying an existing user and setting a predefined IP address range to restrict which machines the user can use to sign in.
When creating or editing users, you can restrict user access by setting a range of allowed IP addresses from which they can sign in. This option prevents users from using the credentials of another user outside a corporate environment. You can also restrict user access to a specific machine.
To automate this process, particularly for a large number of users, we recommend using automated provisioning.
Before you begin:
- If you plan to restrict the user to a specific IP address range, ensure you know the user's IP range. If you set the IP range incorrectly, the user can't sign in.
- Review the user roles and permissions, and the requirements, so you know which UI roles or API roles to assign.
To complete this task:
-
Sign in to the Veracode Platform.
-
From the gear icon
, select Admin. The Administration page opens.
-
On the Users tab, select Add New User.
-
In the User Settings section, enter the user's first name, last name, and email address.
-
Select from the following options:
-
User Type: to create an account for a human user, select UI User (the default). To create an account for a non-human user, select API User. The options change based on your selection.
ImportantWhen you select Save to create the account, the selected user type (UI user or API user) sets the user type for the account, and you can't change it. For example, if you create a UI user, you can't change it to an API user and vice versa. You must create a new account with the desired user type.
-
Login Enabled: to enable login to the Veracode Platform, select Yes (the default). To disable login, select No.
-
Login Type: to require the user to sign with a password, select Password (the default). To sign in using single sign-on (SSO), select SAML and configure SAML access.
-
Requires MFA: to require multifactor authentication (MFA) during sign in, select Yes. The default is No.
-
Restrict Login IP: to restrict the IP range for signing in to the Veracode Platform, select Yes and complete the following steps. The default is No. For a UI user, set the Restrict Login IP to Yes.
a. In the Allowed IP Addresses field, enter a comma-separated list of allowed IP addresses. You can enter an address range using a wildcard (e.g.
74.0.0.*) or a range (e.g.74.0.0.[0-99]). Wildcards are only valid in the last octet of the address; i.e.,74.0.*.*is not a valid range. Ensure you enter externally valid IP addresses, and not private IP addresses such as10.0.0.x.b. To apply the valid IP address ranges to the user, select Save.
-
-
In the Access Settings section, select from the following options:
-
Team Memberships: to add the user to one or more teams, select Select Teams and select the team names. If you're creating an API user account, you can restrict it to selected teams or, to give it access to every application in its organization, select No Team Restrictions.
-
User Roles: select the checkbox next to each UI user role or API user role to assign to the user. If your organization uses custom roles, those roles also appear.
ImportantAssigning the eLearning role has special implications.
- Allowed Scan Types: this field opens depending on which checkbox you select for User Roles. You can select to allow the user to submit all scan types or restrict the user to specific scan types.
-
-
Optionally, in the Metadata section, enter custom metadata for the user in the Custom fields. These metadata fields are visible in the eLearning Account Report. You can use these reports to aggregate eLearning statistics by different values that may be unique to your organization.
-
To create the user, select Save.
-
If you created an API user, ensure the user has set up API authentication.
Creating an account and configuring authentication can take up to one minute to complete.
Copy a user
Create a user manually by copying an existing user. This action copies the user’s access settings and metadata to the new user.
Before you begin:
-
You can only copy the following users:
- Users who don't have the Administrator or Security Lead role.
- If you have the Team Admin role, the user must be a member of a team you manage.
- If your organization created the user with Just-in-Time (JIT) Provisioning, the JIT configuration must have the User Data Updates option set to Prefer Veracode User Data.
To complete this task:
- Sign in to the Veracode Platform.
- From the gear icon
, select Admin. The Administration page opens.
- On the Users tab, in the All Users table, locate the user to copy.
- Select Actions > Copy User. The Add New User page opens.
- Enter the user's first name, last name, and email address. The remaining settings match those of the user you copied.
- Optionally, change any of the settings or accept the copied settings. For details about each field on the Add New User page, see Create a user.
- To create the user, select Save.
- If you created an API user, ensure the user has set up API authentication.