---
title: User management UI and common tasks
source: https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-ui-and-tasks
---

This doc explains how to [find and use the user management UI](#where) and how to do some [common user management tasks](#workflow).

## User management UI [#where]

To find your New Relic organization's user management options: From the [user menu](https://docs.newrelic.com/docs/accounts/accounts-billing/general-account-settings/intro-account-settings), select **Administration**. Here are the user management-related UI pages you can find there:

-   **[User management](https://one.newrelic.com/admin-portal/organizations/users-list)**: Use this to add users, update user type, manage users' groups, approve user upgrade requests, and control session settings.
-   **[Invitation approval](https://one.newrelic.com/admin-portal/organizations/invitation-approval)**: This is where you can approve users to be added to New Relic. These users are not yet considered provisioned and are not billable.
-   **[Feature control manager](https://one.newrelic.com/admin-portal/feature-control-management/home)**: Use this to [activate and manage Intelligent Observability features](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/feature-control-manager) across multiple accounts in your organization.
-   **[Access management](https://one.newrelic.com/admin-portal/organizations/organization-detail)**: The primary interface for managing RBAC, organized into four dedicated tabs:
    -   **[Groups](https://one.newrelic.com/admin-portal/organizations/groups)**: Create and manage user groups, and assign users to groups
    -   **[Accounts](https://one.newrelic.com/admin-portal/organizations/accounts)**: Create and manage accounts within your organization
    -   **Roles**: Create and manage custom roles with explicit scope selection (organization, account, or entity-level)
    -   **Access Grants**: Create access grants that link groups to roles over specific targets
-   **API keys**: Use the [API keys UI](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys) to view and manage your users' API keys.
-   **Domain capture**: Use domain capture to route your users into the right place when they attempt to sign up for New Relic. [Learn more about domain capture.](https://docs.newrelic.com/docs/accounts/accounts-billing/account-setup/domain-capture)
-   **Authentication domains** ([link to UI](https://one.newrelic.com/admin-portal/centralized-admin-user-auto-provisioning/home)): Use this to control how your users are added (from New Relic or from an identity provider), how they log in (manually or via SAML SSO), and more. For details, see [Authentication domains](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/authentication-domains-saml-sso-scim-more).

For tips on managing users, see [Common tasks](#workflow) and our [User management videos](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-mgmt-videos).

## Requirements [#requirements]

The easiest way to see what your user management permissions are is to go to the [user management UI](#where) and see what you have access to.

Some user management requirements and restrictions:

-   To add and edit groups and roles, your organization must have [Pro or Enterprise](https://newrelic.com/pricing) edition.
-   Permissions-related requirements:
    -   Requires a [user type](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-type) of core user or full platform user.
    -   Most user management permissions require organization-scoped roles with authentication domain management permissions.
-   To avoid configuration conflicts, try to ensure that only one person in your organization is managing users at a time.

## UI details [#user-mgmt]

Here's a screenshot of the **User management** UI. We'll explain the column headers below.

![User management UI](https://docs.newrelic.com/images/accounts_screenshot-crop_user-mgmt-ui.webp "User management UI")

-   **Name**: The user's name.
-   **Email**: The user's email address. For users with `Pending`: This user has been added but has not yet verified their email. Even in the `Pending` state, a user is considered provisioned and is therefore billable if they're a core or full platform user.
-   **Type**: The user's [user type](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-type).
-   **Last active**: The last date a user was logged in to the platform. (This does **not** track use of our APIs that require a user key.) This can be useful for deciding to downgrade a user to a lower user type.
-   **ID**: A user's New Relic-assigned ID.

For information about the groups that users are in, you can download a TSV file from the UI or [use NerdGraph](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-groups/#query-user-groups).

## Tips on common user management tasks [#workflow]

Here are some user management tasks you might want to do:

**Learn about users**

To learn about your users, go to the **User management UI** and examine specific users for details. You can also go to the **Access management** UI to examine groups: the roles those groups have, and the users in each group.

To see all your users and their group memberships, you can [use NerdGraph](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-groups#query-user-groups).

**Add users**

Note that adding users directly to New Relic means users with a billable user type are immediately billable, regardless of whether those users are `Pending` and haven't yet logged into New Relic. Options for adding users via the user management UI include:

-   On the [**User management** UI](#where), select **Add user**.

-   On the [**Access management UI**](#where), when creating or editing a group, add a user to that group.

    You can also use the **Invite users** feature. To use that, go to the [user menu](https://docs.newrelic.com/docs/accounts/accounts-billing/general-account-settings/intro-account-settings) and click **Add user**. Details on inviting users:

-   If you have organization-scoped roles with authentication domain management permissions, this takes you to the **Add users** UI, where you can add users directly.

-   If you don't have that permission, you can invite a teammate. This requests review by an admin of that user being added to New Relic. Pending invites that haven't been reviewed are marked as [`Pending invite approval` in the user management UI](#user-mgmt). When an admin reviews an invited user, they complete the **Add user** workflow and that user is considered added in New Relic.

    Some important points about adding users:

-   You can also use [our NerdGraph API to manage users](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-users).

-   If you're using [automated user management](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/automated-user-provisioning-single-sign), you can only add users from your identity provider.

**Edit a user's type**

Before changing the user type for a user, we recommend you understand:

-   [How to decide on a user type](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-type#choose-user-type).
-   [How users are calculated](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-pricing-billing/user-count-billing), including tips on how to time adding new users, or adjusting their user type.
-   [User downgrade rules](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-pricing-billing/user-count-billing#user-downgrade-rules).
-   Using [automated user management](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/automated-user-provisioning-single-sign)? You have [other options for managing user type](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/authentication-domains-saml-sso-scim-more/#user-upgrade).

    To change the user type of users in the UI:

1.  From the [**User management** UI](#where), click the checkboxes for the users whose user type you want to edit.
2.  Once you start selecting users, an option will appear for **Edit type**.

    You can also edit the user type and group of a specific user by clicking on that user.

    For how to use our API to manage user information, see [Manage users with NerdGraph](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-users).

    To manage how users upgrade their user type, see the [authentication domain settings](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/authentication-domains-saml-sso-scim-more/#user-upgrade).

**Bulk edit users**

To edit settings for multiple users at a time:

1.  Go to the [**User management** UI](#where) and select the checkboxes for the users whose group or user type you want to edit.
2.  Editing options will appear at the top of the UI.

    Note: if you're using [automated user management](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/automated-user-provisioning-single-sign), groups must be edited from your identity provider.

**Bulk import users**

To import multiple users into New Relic at once, you have these options:

-   **SCIM provisioning (recommended for ongoing management)**: Set up [automated user management](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/automated-user-provisioning-single-sign/#how-to) to automatically sync users and groups from your identity provider (such as Azure AD, Okta, or OneLogin) to New Relic. This is the best option for organizations that want to manage users in bulk and keep them synchronized. Requires [Pro or Enterprise edition](https://newrelic.com/pricing).

-   **SCIM API (for one-time bulk imports or custom integrations)**: Use our [SCIM API](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/scim-support-automated-user-management/#create-user) to programmatically create users.

-   **NerdGraph API (for scripted imports)**: Use our [NerdGraph API](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-users/#create-users) to create users individually, which can be scripted for bulk operations.

    > #### 💡 TIP
    >
    > New Relic doesn't currently support direct CSV or spreadsheet upload for bulk user imports. For bulk importing, use one of the automated methods above.

**Assign users to manage other users**

There are two options for giving your users the ability to manage other users:

-   Organization-scoped roles with authentication domain management permissions grant users organization-wide capabilities related to managing users, groups, and authentication domains.
-   The [Group admin](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts#group-admin) role is much more constrained: it gives users the ability to add and remove users for a specific group.

    To give organization-wide user management abilities, you can add a user to the default **Admin** group, which has organization-scoped roles with these permissions. You can also create a custom group and assign it organization-scoped roles with authentication domain management permissions.

    For a tutorial on common user management tasks, see the [user management tutorial](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/account-user-mgmt-tutorial).

**Delete users**

To delete users: go to the [**User management** UI](#where) and select the checkboxes of one or more users. Then click **Delete users**.

When you delete a user, the following user assets are removed:

-   Favorites
-   Weekly email settings
-   Email opt in/out preferences
-   User-specific [user keys](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#user-api-key)
-   New Relic apps [NerdStorage data](https://docs.newrelic.com/docs/new-relic-solutions/build-nr-ui/nerdstorage)

**Export a spreadsheet of users**

To export a list of all users and their details (names, email addresses, current user type, groups, user ID): From the [**User management** UI](#where), click the download icon beside the **Add user** button. There's an option for downloading a list of all users in that authentication domain.

Alternatively, to export a subset of users, first select the users you want to export, and then hit the download button.

**Give users access to accounts and roles**

See our [user management tutorial](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/tutorial-add-new-user-groups-roles-new-relic-one-user-model).

**Create new custom groups and roles**

See the [user management tutorial](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/tutorial-add-new-user-groups-roles-new-relic-one-user-model).

**Set up SAML SSO and/or SCIM provisioning**

You can use a single sign-on identity provider to log in to New Relic using SAML SSO. For bulk user management, you'll also want to use SCIM provisioning (also called automated user management). It enables you to automatically sync users and groups from your identity provider to New Relic.

SCIM provisioning offers these benefits for bulk user management:

-   Automatically import and sync large numbers of users from your identity provider
-   Keep user information up-to-date automatically
-   Manage users and groups centrally from your identity provider

    To set up SAML SSO or SCIM provisioning, refer to [Get started with SAML SSO or SCIM](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/introduction-saml-scim). Note that these features require the [Pro or Enterprise edition](https://newrelic.com/pricing).

**Control how users upgrade their user type**

See the [authentication domain settings](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/authentication-domains-saml-sso-scim-more/#user-upgrade).

## Name field requirements [#name-field-requirements]

When creating or updating a user, the `name`, `given_name`, and `family_name` fields must meet these requirements:

| Rule                           | `name`   | `given_name` / `family_name` |
| ------------------------------ | -------- | ---------------------------- |
| Maximum length: 250 characters | Enforced | Enforced                     |
| URLs                           | Blocked  | Blocked                      |
| Email addresses                | Blocked  | Blocked                      |
| Domain names                   | Blocked  | Blocked                      |
| Emoji                          | Blocked  | Blocked                      |
| Control characters             | Blocked  | Blocked                      |
| Invisible Unicode              | Blocked  | Blocked                      |
| Equal sign (`=`)               | Blocked  | Allowed                      |

> #### 💡 TIP
>
> Names with hyphens, apostrophes, accented characters (like ñ or ü), periods, spaces, and non-Latin scripts are all valid. Dot-separated names such as `firstname.lastname` are allowed because the domain check only blocks strings ending in a registered top-level domain (like `.com`, `.net`, or `.co.uk`).

These rules apply across the UI, [SCIM API](https://docs.newrelic.com/docs/accounts/accounts/automated-user-management/scim-support-automated-user-management), and [NerdGraph API](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-manage-users). Validation runs when a user is created or when a name field is updated. Existing users with non-conforming data are not affected unless they update the validated field.

## Use our API [#api]

To use our API to manage accounts and users, see our [NerdGraph tutorials](https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph/#tutorials).

## Track changes [#track-changes]

To see an audit log of changes to your account, including user management actions, you can query the [`NrAuditEvent`](https://docs.newrelic.com/docs/insights/insights-data-sources/default-data/nrauditevent-event-data-query-examples).
