# Account

The Account Settings page allows you to manage your Reblaze user accounts.&#x20;

## **Tab: Your account details**

![Your account details](/files/-Mbf7Xj7rdwV7FneLmnV)

### Basic account settings

From this tab, you can reset your password, name, and phone number.&#x20;

### Settings for OTPs (One Time Passwords)

Reblaze uses 2FA (two factor authentication). There are several options for sending an OTP when you login:

* If only an email address is provided, the OTP will be sent via email.
* If a phone number is provided, the OTP will be sent over SMS message.
* As an alternative, you can also get a QR code for use in apps such as Google Authenticator (available for both [Android](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2) and [iPhone](https://itunes.apple.com/il/app/google-authenticator/id388497605)).&#x20;

### API Key

This tab also offers a personal API key, to be used in all requests to the Reblaze API.

## Tab: Users management

![Users management](/files/-MbfCXEOFboiXbjOOm8l)

This tab allows you to manage users that are attached to your organization. It is only available to users with administrator permissions.

### Administration

An admin can:

* Create a new user
* Edit an existing user
* Reset a user's password
* Delete a user

When a user account is being edited, this will appear:&#x20;

![Edit User](/files/-MbfDPlAnfIyj53tU67g)

The available Access Levels are:

* *Viewer*: can see the [Traffic](/v2.20.2/product-walkthrough/reblaze-traffic.md) section, i.e. the Dashboard and View Log.
* *Editor*: has all Viewer permissions, and can also configure security rulesets and policies in the [Security](/v2.20.2/product-walkthrough/security.md) and [Settings](/v2.20.2/product-walkthrough/settings.md) sections.
* *Organization Admin*: has all Editor permissions, and can also manage users via the Users Management page.
* *Reblaze Admin*: has all Organization Admin permissions, and can also edit and view the Notes, Init and Run pages.

## **Tab: Single sign on configuration**

![](/files/-MbfPGiAkOTqtIEx7BkK)

This tab allows SSO to be configured so that users have the ability to log into Reblaze with their **Okta** or **Microsoft** accounts.

Configuration options will vary depending on the type of account.

### Set up Okta SSO

#### **1. Go to** [**Okta**](https://www.okta.com/)**, register and create an application:**

Go to `https://{YOUR ACCOUNT}-admin.okta.com/admin/apps/active`

Click `Add Application` → `Create New App`

Choose `Platform: Web`, `Sign on method: SAML 2.0`

![](/files/LbfF8e8Dp7nrR5eTratt)

#### **2. Name it, setup links and attributes:**

*Single sign on URL*:&#x20;

`RBZ_SSO_ASSERTION_URL` env var. Value should look like: `https://{CUSTOMER_DOMAIN}/sso/saml20/signon`.<br>

*Audience URI (SP Entity ID)*:&#x20;

`RBZ_SSO_AUDIENCE_URL` env var. Value should look like: `https://{CUSTOMER_DOMAIN}/sso/saml20/audience`<br>

![](/files/qKIokFqU1tBwC3mt6qFK)

*Attribute Statements:*<br>

emailaddress: `user.email`<br>

displayname: `user.firstName + " " + user.lastName`<br>

groups: `appuser.rbzgroups`

![](/files/44JNWBfXg77sL1AJaQPt)

#### **3. Custom User profile**

In order to pass Admin group ID we need to add custom attribute to the user groups.\
Directory > Profile Editor > Apps > Click on Profile<br>

![](/files/eKlaEhaewXUwNbestdCv)

![](/files/9WksXmlhj6UPgknugSS6)

Next step will be to map it.&#x20;

Directory > Profile Editor > Apps > Click on Mappings

![](/files/Y1GjbLosTNuoNVWRzNJP)

**4. Assign the application to users**

Create user groups for two possible access levels: Admin and Read-Only access.&#x20;

Assign users to it. Group name is the string you need for `RBZSSOSAML2_ADMINGROUP` or place the group name into the Reblaze console SSO settings.

![](/files/q7EAYUyU2N4KuQP1aefz)

And in your just-created Application settings:

![](/files/jq7PMMMwswIeTWvJHptT)

On the assignment step, a value will be required for the custom attribute which we configured before. For the admin group the value will be same as on `RBZSSOSAML2_ADMINGROUP`, while for the read-only group value it can be anything else.

#### **5. Get Metadata XML link:**

Add the **URL** to the XML metadata file to the `RBZ_SSO_META_URL` env var (and/or for Provider URL field in admin)\
The URL example: <https://vreagles.okta.com/app/exkl1t3p61ek810CP5d6/sso/saml/metadata><br>

![](/files/RAhsIfeskAdonld5cToV)

\ <br>

#### **6. Where to get** `RBZ_SSO_IDP_ISSUER`**:**

Go to Applications, choose yours, `Sign On` tab, click on `View Setup Instructions`

![](/files/t4ilqROP54JyUNQ0j74r)

There you'll find Identity Provider Issuer:

![](/files/p5lNGaeoP7C6wjr9fg5X)

### Set up Microsoft Azure SSO

**1. Go to** [**Azure Portal**](https://azure.microsoft.com/en-us/account/) **→** `Enterprise applications`

**2. Choose** `+ New Application` **→** `+ Create your own application`**:**

![](/files/avGmSwmZUgrUiGTItxnE)

**3. Choose option** `Integrate any other application you don't find in the gallery (Non-gallery)` **(this option will create SSO app):**

![](/files/23MATEN6Nm813N9Ziogb)

**4. Go to** `Single sign-on` **section and choose** `SAML`**:**

![](/files/lQoBTEluP35Ska7YLPSF)

**5. Set up appropriate links:**

![](/files/JMrYp0qZnC8rCWvgGqdL)

`RBZ_SSO_IDP_ISSUER` should be provided by a customer and have to be unique for the customer’s SSO applications. The best option is to just use something like: `https://customer_domain.com?sso=123`. (the **IDP** **Issuer** field (in the console) should be identical to the **Identifier** field (in Azure))\
\
**6. Get Metadata XML link and add to** `RBZ_SSO_META_URL` **environment variable:**

![](/files/Ic2ZNMUiKRBCr9RprHLC)

&#x20;**7. Setup** `user.groups` **in User Attributes & Claims, so it send all groups related to the user:**

\
Click on “+ **Add a group claim”,** choose:

* **All groups**
* Source attribute: **Group ID**

![](/files/wcjcp11m2K8ll0VoMHDK)

![](/files/guG4xes0XLg8i87dW53p)

**8. Add a user as a member of the application:**

![](/files/DxsD5Clgx7yrcss2IUYg)

**9. Get admin group ID from Azure and put it into** `RBZ_SSO_ADMIN_GROUP` **environment variable:**\
Go to `Azure Active Directory` → `Groups`, create a group.

`Object ID` is the string you need for `RBZ_SSO_ADMIN_GROUP` or place the group ID into the Reblaze console SSO settings:

![](/files/P7oxmmbbsmamecDhopjB)

And assign a user to the group:

![](/files/bNT2jzn5ZysqJIsHROVv)

<br>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://waap.docs.link11.com/v2.20.2/product-walkthrough/settings/account.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
