In This Article: Learn how to bring new users into your Ontario environment through secure Azure-backed invitations, role assignment, and seamless SSO onboarding.
Â
How User Access Works
Ontario leverages Microsoft Azure Entra ID to provide enterprise-grade security through guest access invitations. Users authenticate with their existing work credentials via SSO—no additional passwords required.
User Invitation Flow
You Create User
Add details & role
Ontario Sends Email
Invitation link sent
User Logs In
SSO authentication
Access Granted
Ready to work
Key Capabilities
Ontario's user management system provides flexible control over who can access your environment and what they can do once they're in.
Email-Based Invitations
Send secure invitations via email that guide new users through the onboarding process. Users accept invitations by logging in with their work credentials.
Role Assignment
Assign environment-level roles during user creation. Choose between Admin (full access) or Viewer (read-only) roles to control what users can do.
Group Membership
Add users to groups during creation to streamline permissions management. Groups provide an efficient way to manage access across multiple projects.
Project Access
Connect users directly to specific projects during setup. This ensures new team members have immediate access to the work areas they need.
Creating a New User
Navigate to the Users tab from the Ontario Landing page and click the Create + button. Complete the form with the following information:
| Field | Required | Description |
|---|---|---|
| First Name | Yes | User's first name as it will appear in Ontario |
| Last Name | Yes | User's last name for identification |
| Yes | Work email address—must be accessible to receive invitation | |
| Ontario Role | Yes | Environment-level role: Admin (full control) or Viewer (read-only) |
| Group(s) | Optional | Add to existing groups to inherit group-level permissions |
| Projects | Optional | Assign direct access to specific projects |
Screenshot: Create User Modal
The Create User dialog with all form fields visible, including dropdown menus and the Add Project button
Pro Tip: Use Groups for Efficiency
Rather than assigning users to individual projects, add them to groups during creation. This streamlines permission management as your team scales and makes it easier to adjust access across multiple projects simultaneously.
Understanding the Invitation Process
When you click Save, Ontario provisions the user in your Azure Entra tenant and automatically sends a secure email invitation. This guest access model enables SSO authentication while maintaining security boundaries.
Learning Check: Invitation Details
How long are invitation links valid?
When does the invitation get accepted?
What New Users Experience
1. Receive Email
Welcome email arrives with secure invitation link
2. Authenticate
Log in using existing work email credentials
3. Start Working
Instant access to assigned projects and resources
Managing User Status
Once a user is created, their status in the Users table indicates whether they can currently access Ontario. Users are either Active or Inactive.
Active
User Can Access Ontario
User has completed the invitation process and successfully authenticated. They have full access to their assigned projects, groups, and resources.
Ready for collaboration and task assignment
Inactive
User Cannot Access Ontario
User has been deactivated by an administrator. They cannot log in or access any Ontario resources until reactivated. Use this status when offboarding team members.
Can be reactivated from the action menu
Screenshot: Users Table with Status Indicators
The Users table showing multiple users with different status badges (Active, Inactive) and the three-dot action menu with options like Edit, View details, Assign to group, and De-Activate/Activate
Troubleshooting Invitations
User didn't receive the invitation email
- Verify the email address is correct in the user details
- Check their spam/junk folder for the invitation
- Confirm their organization allows emails from Ontario/Azure
- Contact Ontario Support if the email still hasn't arrived
Invitation link doesn't work
- Ask user to try a different browser or clear cache
- Verify their work email can access Azure-authenticated services
- Ensure their organization's Azure AD/SSO configuration is properly set up
- Contact Ontario Support for assistance with authentication issues
User cannot log in after accepting invitation
- Confirm they're using the same email address as the invitation
- Verify they completed SSO authentication fully
- Check that their user status shows as Active in the Users table
- Contact Ontario Support if authentication problems persist
Bulk User Operations
Need to onboard an entire team? While you can create users individually, adding 10+ users at once is more efficient through bulk import support.
Contact Ontario Support for Bulk Import
Provide a spreadsheet containing user information (names, emails, roles, groups, project assignments), and our team will handle the bulk creation process. This approach is:
- Faster than manual entry
- Reduces errors from repeated data entry
- Available at no additional cost
- Ensures all users receive invitations simultaneously
Prepare Your List
Include: First name, Last name, Email, Role, Groups, Projects
Best Practices
Verify Emails
Double-check email addresses before sending invitations. Typos require recreating the user account.
Right-Size Roles
Start with Viewer permissions. You can always upgrade to Admin later as needs evolve.
Use Groups
Add users to groups during creation rather than individual projects. This scales better as teams grow.
Monitor Status
Check the Users table regularly for Pending status. Follow up if users haven't onboarded within a few days.
What's Next: User Administration
Now that you know how to add users, explore how to organize them into groups and manage their access across your Ontario environment.
Managing Users and Groups
Learn how to organize users into groups, manage group memberships, and efficiently control access across multiple projects.
User Roles and Permissions
Understand Ontario's dual role system, learn the differences between environment-level and project-level roles, and discover how to assign appropriate permissions.
Ready to build your team: Ontario's Azure-backed invitation system provides enterprise security with user-friendly onboarding. Use groups for scalability, monitor pending invitations, and reach out to Ontario Support for bulk imports when onboarding larger teams.
Comments
0 comments
Article is closed for comments.