---
version: "2026.1.0"
language: "en"
---
# User Management

In **User Management**, you can define, manage, and control your team members' user roles and privileges directly from Leapwork's settings.

After installing the Controller, your first step is to create user accounts for everyone who needs access to Leapwork. This can be done by creating users directly in Leapwork or by configuring access through Active Directory (AD).  
By default, an **admin user account** is created during installation. The password is set at that time. For security reasons, the password cannot be recovered, so make sure it is stored securely.  
User management settings are available only when you are logged in with administrator privileges.

## Adding users directly in Leapwork

To add a user:

1. Simply click on the Add user button. The following pop-up then appears:

![image-20260612-150150.png](https://docs.leapwork.com/__attachments/a_5f666cc84f1d84eca278ec009bf189b706927c4595d16cb2fba64e821d94d333/image-20260612-150150.png?cb=ee49e46134c4e6bb54b8919da900a20e)

2. Enter only basic information to create a user account on Leapwork:

* **Full Name**: This is the user's display name and appears in logs, reports, and audit trails.

* **Username**: Used by the user to log into Leapwork Flow.

* **Access Level**: Selected from a drop-down menu, this determines the user's default privileges.

There are four access levels:  

* **Administrator**: Full access to all system functions, including user and asset management, system settings, and audit logs. Administrators can also view the database encryption key.

* **Contributor**: Can create and edit all assets and execute flows, but cannot change system-level settings or access the audit log.

* **Reader** : Has read-only access to all assets by default. However, administrators can allow Readers to **run flows** by enabling the *"Allow Reader to run flows"* option in the **Privileges Settings** tab. Readers cannot modify content unless explicitly granted further privileges.

* **No Access**: Cannot view or edit any content. This level is useful for temporarily revoking access without deleting the user account.

These roles apply to all folders, flows, and sub-flows in Leapwork. For example, a user with the Reader role has consistent read-only access across the platform.

Additionally, [Privileges Settings](https://docs.leapwork.com/leapwork-flow/latest/administration/privileges-settings.md) defined by the Administrator apply globally to all users of a given role, allowing fine-tuned control over what users can do regardless of their base role.

3. Once the user information and access level have been defined:

* **Set a password**: You can either create a password manually or let Leapwork generate one automatically.

* **Enforce password change (optional):** Select the checkbox to require the user to change their password upon first login.

* **Assign the user to a team:** Teams help organize collaboration and manage permissions.

* **Share credentials**: After creating the user account, share the login credentials with the user manually.

Team collaboration and management features are only available in the **Leapwork Enterprise Edition** . These options will not appear in the **Platform Edition**.

### Using Active Directory (AD) to control access

Leapwork supports a mixed user setup, where some users are created directly as users (with a username and password) in Leapwork, and some users get the access via AD.

**Note**: To use AD to control access to Leapwork, both the computer with the user's Flow and the Controller must belong to the same AD. Otherwise, the options below will be unavailable.

In the User Management section, the option **Add AD/SSO** **User** is visible if Leapwork supports AD access control.

To add an access level for either a user or a group from AD:

1. Click on**Add AD/SSO** User button:

![image-20260302-093603.png](https://docs.leapwork.com/__attachments/a_7aa787ea91e9ec9be02172d7e43e095046fab3fdf53a46bd5e58526160bb6412/image-20260302-093603.png?cb=7fcbd5d005da26dbb4afda9f94e96b60)

2. In the **Select Users and Groups** dialog, specify the AD name of a user and/or a group then click OK.

![Picture9-1-20260612-150517.png](https://docs.leapwork.com/__attachments/a_cd2067958744a115238ef352a9d869ad6c4969c8326ff13d7d1e4c88139a5cf1/Picture9-1-20260612-150517.png?cb=e2bd2d9626da0862e62f124a29bd6d41)

3. With the AD entity now selected, specify the access level for the selected entities. In the example below, the Select Users and Groups dialog shows the group name External/test

![Picture3-1-20260612-150829.png](https://docs.leapwork.com/__attachments/a_7b48c8f3a7a2085a87be522381b4c7e4f74d2bf282ca96e655fdf86fa61cb573/Picture3-1-20260612-150829.png?cb=c25c4742ab52ebc348f26bb7fe7a6974)

4. Once the access level is set, click **Save**.

![image-png-Sep-11-2023-10-05-07-3010-AM-20260612-151019.png](https://docs.leapwork.com/__attachments/a_61d22dd25eccb57d218327892ee4a363de17e5d53bfaf5e173d9ad07bd85de98/image-png-Sep-11-2023-10-05-07-3010-AM-20260612-151019.png?cb=bd3ce7084624b52e792c868d856a9f76)  
You can see the new configuration in the access configurations list.

### Add AD (Lightweight Directory Access Protocol (LDAP) User

LDAP integration with Leapwork is a newly added feature. **Connection**tab lets you set up a connection to the LDAP server. To deepen your understanding of LDAP and the Connection tab, you can explore our detailed guide [here](https://docs.leapwork.com/leapwork-flow/latest/administration/connections/lightweight-directory-server.md).

To add an LDAP user or group, from **Settings**:

1. Go to **User Management.**

![image-20260119-140333.png](https://docs.leapwork.com/__attachments/a_8ad3d9a22ac937dafa870c9020d6f79b4827f68b954ba7df314515cf0e2b084a/image-20260119-140333.png?cb=0c7b1e147471b60d8b06899ef92b6e86)

2. Click on **Add AD/SSO User** and a new window open:

3. ![image-png-Sep-11-2023-10-29-00-6932-AM-20260612-151144.png](https://docs.leapwork.com/__attachments/a_b1ec4d92dc6893d1d0f4218086ca7a39b0909470f2926b56d056b90ceafc1aa5/image-png-Sep-11-2023-10-29-00-6932-AM-20260612-151144.png?cb=6a900ac1686ead9c22ff4ee5ab3e48c2)

   Enter the **User** or **Group**name to authorize the user or group in the LDAP directory.
4. Select **Access** from the drop-down menu.

5. Check the **Team checkbox** as needed.

The **Team checkbox** is only for Leapwork Enterprise Edition users).

6. Click **Save**to save the **User**or **Group**.

To the right of the **Add AD/SSO User** button, use the **Edit**, **Delete** and **Export**buttons to modify, remove, or export user profiles to Excel.

### Add SSO User

The Azure Active Directory (AAD) integration with Leapwork is a newly added feature. To learn more about **AAD SSO** and the **Connection** tab, see the related [documentation](https://docs.leapwork.com/leapwork-flow/latest/administration/connections/single-sign-on-sso-connection.md). **Connection**tab lets you set up a connection to the AAD SSO server.  
![image-20260316-124657.png](https://docs.leapwork.com/__attachments/a_55f1982015eebb99068cb6847131bd3c300fad28b126970bb0ef8556c99a3384/image-20260316-124657.png?cb=9cc667297257098ed7401bafcec908df)

To add AD/SSO user or group, from **Settings**:

1. Go to **User Management.**

2. Click on **Add AD/SSO User** and a new window opens:

![image-png-Sep-11-2023-10-05-07-3010-AM.png?width=486&height=290&name=image-png-Sep-11-2023-10-05-07-3010-AM.png](https://docs.leapwork.com/__attachments/a_060bba2eb6e65a97aac37c71134d92ae24d8534d81301e0f8f5f1f589f459b03/image-png-Sep-11-2023-10-05-07-3010-AM.png%3Fwidth=486&height=290&name=image-png-Sep-11-2023-10-05-07-3010-AM.png?cb=70f4b543a9f08b8b97a03b72bbbd8e32)

3. Enter the **User** or **Group** name existing in the Azure Active Directory of the added connection.

4. Select **Access** from the drop-down menu.

5. Check the **Team**checkbox as needed.

The **Team**checkbox is available only for Leapwork Enterprise Edition users).

6. Click **Save** to save the **User** or **Group**.

To the right of the **Add AD/SSO User** button, use the **Edit** , **Delete** and **Export** buttons to modify, remove, or export user profiles to Excel.  
![image-png-Sep-11-2023-10-29-00-6932-AM-20260612-151448.png](https://docs.leapwork.com/__attachments/a_2164265434d95e5a5041cb4eabc6c872426aa109327629698364f57234b09318/image-png-Sep-11-2023-10-29-00-6932-AM-20260612-151448.png?cb=6a900ac1686ead9c22ff4ee5ab3e48c2)

### Login options

When a user accesses the Flow the first time, they can choose how to log in - using a username and password or using the AD/SSO.  
![Picture5-1-20260612-151533.png](https://docs.leapwork.com/__attachments/a_d9669143e9b89f3665e592851eb9877931969ce41123e948aef3f8b5d25cbad5/Picture5-1-20260612-151533.png?cb=4af724d258961fb5dc09d486e7318549)

If Leapwork user is selected, the user will have to enter the username and password - typically provided by the administrator in an email or similar:  
![Picture6-20260612-151548.png](https://docs.leapwork.com/__attachments/a_f5dbacc7c42e2d6bfd787b6e84ce30e061c7b9a8f0cdf6c4338c02abcd34be46/Picture6-20260612-151548.png?cb=2141f2db31e6504cf7dc288cb78d91f3)

In case the user selects Active Directory user, the current Windows user is evaluated against the AD configurations in the user management section:  
![Picture7-1-20260612-151625.png](https://docs.leapwork.com/__attachments/a_e01b594fae01ada2ed7b48d176b4724a7ad19913677f47d5ce9e3418f24b28a4/Picture7-1-20260612-151625.png?cb=3155a7b5a161c5e01a190f30fcdcbf72)

If a Windows user is member of more than one AD group, and the different AD groups allow different access levels in Leapwork, then the user will be given the highest privileges.

* In case you select SSO user, the current Windows user is evaluated against the SSO configurations in the user management section.

![image-png-Sep-11-2023-11-46-17-9227-AM-20260612-151729.png](https://docs.leapwork.com/__attachments/a_2ce72f2c743eff3e6e5b61071f7f97e5880ad85adaff4039070b4d6dc415916d/image-png-Sep-11-2023-11-46-17-9227-AM-20260612-151729.png?cb=667fe0d6dba7cdab4b2c8558cc93332f)  
**Note**: Users with valid SSO credentials added as SSO users will be redirected to the authentication page, after which their credentials are remembered.  
![image-20260302-114735.png](https://docs.leapwork.com/__attachments/a_d7b0ab2d5e62dced7dda379dd6037e16d9127dc99615326f283adb1c3bc15f4b/image-20260302-114735.png?cb=d793376a789e2de11d8da185def12d95)

For all login types, you only need to sign in once.  
After the first successful login, Leapwork remembers your session.