People and sign-in.
Admin → Users is where accounts, groups and sign-in live. Your own name, password and keys are under Profile.
People
The list shows each person's name, email, role, status and last sign-in. Invite people by email. An account can be active, invited, turned off or locked.
Turning an account off stops that person signing in, and their links stop working. Their files stay. You can set a home folder, a quota, rights and a speed limit. If someone loses their authenticator app, reset it here so they set it up again at the next sign-in.
Groups
A group is a list of people and the folders they all reach. Adding someone to a group gives them every folder the group has been shared. Removing them, or deleting the group, ends that access. No account or file is deleted.
On a folder, members can be given:
- Can view: browse, download, and send packages from these files.
- Can edit: that, plus upload new files and folders.
- Full access: that, plus delete and replace files.
Access to a folder covers everything inside it. Rights add up, so a second share of a folder already covered can only widen what members can do there. How spaces are granted is also covered in Storage spaces.
Sign-in rules
Admin → Users → Sign-in rules sets the password length, how many wrong attempts lock an account, whether an authenticator app is required, and how long a session lasts. These apply on every plan.
Sign in with a work account
Business and Enterprise can let people sign in with the account they already have at work.
- OpenID Connect is under Admin → Users → Single sign-on. You give the provider address (an https issuer URL), the client ID and the client secret. The secret is stored encrypted and is not shown again; leave it blank to keep the one already saved. You can change the wording of the sign-in button. If sign-on is on but the provider cannot be reached, people can still sign in with a password.
- SAML covers Okta, Microsoft Entra ID, Google Workspace and ADFS.
- LDAP and Active Directory covers directory passwords, nested groups and the hourly sync.
Your account
Profile is where you change your own name, password and authenticator app. API keys for scripts are under Profile → API keys, and are documented in the API reference. Administrators set the longest life a key may have under Admin → Security → API keys.