Manage Users in the Dashboard
Two user types can access the Dashboard. Invictus manages Local users. Your tenant manages Microsoft Entra ID users.
Prefer Entra ID users for security.

- Entra ID
- Local
Requires a synced Entra ID group.
The Dashboard works with users in Entra ID groups.
See syncing groups to set them up. Entra ID users sign in with the Make sure the group has a role assigned. Without one, the Dashboard won't work. Click the delete icon to remove a user from the Dashboard. This action doesn't remove them from Entra ID. Entra ID users have no direct role. They get their role from their group. Entra ID users have no direct role. They get their role from their group.
If the group can access a flow, so can the user. To use forgot password, create an Entra ID app. Add the Go to to add the backup email address for 'Forgot password' emails. The Dashboard may use any email in the tenant as the sender.Add an Entra ID user
Delete an Entra ID user Only Admins
Edit an Entra ID user's role Only Admins
Configure forgot password procedure Only Admins
Mail.Send permission. OAuth 2.0 uses it to send emails.
The Dashboard manages local users. You can assign roles and delete them at any time. Go to Click the delete icon to remove a user. Local users have a direct role assigned. Click the icon to edit a local user's Role . Set up the email server for password resets. Go to Add a local user Only Admins
Delete a local user Only Admins
Edit a local user's role Only Admins
Configure forgot password procedure Only Admins
Forgot password setting Description Host The host address of the email server. For example: "smtp.gmail.com" for Gmail.Port number The email server port. Default is 587. Email key vault key The Key Vault secret name for the sender email address (bundled with Invictus). Password key vault key The Key Vault secret name for the sender email password (bundled with Invictus). Enable SSL Enable SSL. Most email providers require it.
Unlocking a user Only AdminsNew since v6.3
Too many failed sign-in attempts lock a user out. System admins can unlock them via the button.