Manage#
The Manage Domains page contains options to configure accounts, mailing, and generic resources.
Accounts#
The list of all account in the domain is present here, along with information on their type and status.
The list can be filtered using the text field above the list, while a new account can be created using the + button.
A click on any account will open a new panel that contains a number of information and options that can be modified. When editing a user’s account, most of the option are the same that can be found in the Create an Account section and are organised in tabs.
On the panel’s top right corner, buttons allow to VIEW MAIL of the user, that is, to access the user’s mailbox and to DELETE the user. Upon deletion, all the e-mails, contacts, calendars, and files owned by the user will be deleted: in other words, all user’s blobs and associated metadata will be removed from Carbonio.
Options defined in the user’s COS are inherited, but can be modified for any individual user. The values that have been modified are accompanied by a circular arrow icon. If you hover on that icon, you will see the inherited value, while if you click on it you will restore the COS value.
The configuration options available for each account are grouped in several categories. Click on each button to go to the respective category.
General configuration options of the account
Personal information about the user and its role
Options about e-mail management and features available to users
Default values for preferences that can be overridden by the user
Password policies, OTP, backup and other security-related options
Additional Domain Administration roles
Delegation options
General
This tab contains all the options provided during the account creation, plus other options, including:
Whether this account is included in the Backup
The number of aliases of the account
-
The type of the account, which is one of
Normal: a Regular user
DelegatedAdmin: a Delegated (Domain) Administrator
Admin: a Global Administrator
System: special accounts used by Carbonio, i.e., GALsync, spam and ham training, and virus quarantine
External: an account that does not use Carbonio for authentication
Upon clicking the arrow on the right-hand side of the option, the Administration tab will open, to allow changing the user’s type of account.
-
Quota settings: Use the Unlimited option to remove quota limits for the account. If Unlimited is disabled, specify a maximum quota value for the account. Click the Reset button to discard the account-specific setting and restore the quota value inherited from the assigned Class of Service (COS).
For more information about quota management, see Manage an Account Storage Quota.
-
To force the user to change password at the next login
Note
An Admin can not change the password of a user, only wipe it, so the user is forced to change it on the next login attempt.
To remove the user’s password from LDAP
The COS the user belongs to
The Distribution List memberships
To move a user to another domain, which must be defined on the same server, by writing the new one in the Domain Name
The ABQ status: Strict, Permissive, Interactive, or Disabled (see ABQ Modes for details)
How many OTP devices the user has.
At the bottom, it is possible to see all the user’s open sessions, which can be terminated by selecting one and clicking END SESSION button on the top right of the list.
Profile
Data in this tab represent the user’s phones, company, and address. They can be managed by both the user and the Administrators.
Configuration
The options listed here allows to specify e-mail forwarding and to enable various features related to the everyday use of Carbonio.
Forwarding
These options allow to forward all the e-mail sent to the user to a different address.
User can specify mail forwarding filter this option is needed by users to allow them to create e-mail filter to forward e-mails to a different address.
Forwarding address specified by the user is useful if, for example, you as a rule don’t allow users to forward e-mails, but want or need to make an exception.
Mail Transport
This advanced option proves useful only in split-domain or migration scenarios.
Features
It is possible to prevent the user to access some of the Carbonio features by using the switches for the various Components. For example, Web feature means access to the web interface and Mobile App allows access via Carbonio mobile applications.
Chat
Options here allow to configure the Chats
- General Settings
-
The only option here enables or disables the Chats.
- Messaging & Presence
-
Define the time out after which text messages can be modified or deleted and whether a user can see other users’ status and read receipt.
- Private and Group Chats
-
These options limit the user ability to create new private chats and groups and limit their number and the file size of files that can be shared.
- Video Calls
-
Enable video call and the possibility of users to record video calls and use virtual backgrounds.
- Sharing & Attachments
-
Enable files upload in chats and calls and set the file’ maximum size.
User Preferences
This tab contains settings that control how users view, manage and interact with their data across the platform. These preferences affect the behavior and appearance of emails, calendars, and contacts, shaping the overall user experience in the client interface.
Mail Options
The Mail Options section controls how messages are displayed and managed.
Option |
Description |
|---|---|
View mail as HTML |
Enable or disable HTML rendering for email messages. |
Group messages |
Choose whether emails are grouped by single message or by conversation. |
Auto-delete duplicate messages |
Automatically remove duplicate emails when enabled. |
New Mail Toast Notification |
Enable or disable toast notifications for newly received emails. |
Default Charset |
Define the default character encoding used for emails. |
Receiving Mails
The Receiving Mails section defines how and when incoming messages are handled.
Option |
Description |
|---|---|
Check new email every |
Select the interval for checking new incoming messages from a predefined list of values. |
Auto-reply messages |
Enable or disable automatic reply messages. |
Out of office lifetime |
Define the start and end time for the out-of-office auto-reply. |
Read Receipt Settings |
Configure how read receipt requests are processed. |
Sending Mails
The Sending Mails section controls message sending behavior.
Option |
Description |
|---|---|
Save to Sent |
Enable or disable saving sent messages in the Sent folder. |
Allowed sender addresses |
Specify which email addresses are allowed for sending messages. |
Ask for read receipt |
Enable or disable the ability to request read receipts when sending emails. |
Composing Mails
The Composing Mails section manages email composition preferences.
Option |
Description |
|---|---|
Mail signature |
Enable or disable the email signatures feature. |
Signatures management |
Add, edit, or remove email signatures. |
Note
Signatures can not be assigned to Resources.
Contact Options
The Contact Options section configures contact management behavior.
Option |
Description |
|---|---|
Auto-add contacts |
Automatically add email recipients to the contact list when enabled. |
Use GAL auto-fit |
Enable or disable Global Address List auto-completion. |
Calendar Options
The Calendar Options section defines default calendar behaviors and invitation handling.
Default Settings
Option |
Description |
|---|---|
Time Zone |
Set the default time zone for the calendar. |
Default appointment duration |
Define the default duration for new appointments. |
Appointment reminder |
Set the reminder time (in minutes) before an appointment starts. |
Default calendar view |
Choose the default calendar view (e.g. Day, Week, Month). |
Week start |
Select the first day of the week. |
Default appointment visibility |
Define the default visibility level for new appointments. |
Additional Options
Option |
Description |
|---|---|
Past appointment reminders |
Enable or disable reminders for appointments in the past. |
Send cancellation emails |
Enable or disable email notifications when appointments are cancelled. |
Auto-add forwarded appointments |
Automatically add forwarded invitations to the calendar. |
Add invites with PUBLISH method |
Enable or disable adding invitations using the PUBLISH method. |
Auto-add invited appointments |
Automatically add appointments when the user is invited. |
Auto-decline blacklisted senders |
Automatically decline invitations from blacklisted senders. |
Notify delegated changes |
Enable or disable notifications for changes made by delegated accounts. |
iCal delegation model |
Enable or disable the iCal delegation model for shared calendars. |
Security
Options present here allow to manage the account security.
Services Passphrase
A Service passphrase allows users to connect to Carbonio without the need to provide their own credentials. Please refer to Sections Service Credential Management to learn more details and Services Supported for a list of supported services and example scenarios where passphrases prove useful.
To create a new passphrase, define add a label, then choose a service. A dialog will open, that contains a password. It is important to know that the password will be shown only once, so make sure to store it in a safe place or give them only to trusted people. Moreover, with this password, it will be possible to bypass 2FA authentication even from untrusted networks.
Upon closing the dialog, you will be able to either DELETE the passphrase or to CREATE a new one.
Two-Factor Authenticator
New OTP tokens can be created to allow the user to login by using a QR Code. The code can then be sent by e-mail to the user who requested it. If the recipient can not see the QR Code (for example because the provider does not support HTML e-mails or prevents inline images to be shown), a text equivalent version of the QR Code will be shown (the Secret Code), allowing the user to use it.
It is also possible to completely disable OTP for a user by using the One Time Password Management switch. In this case, the user can not create OTP codes in the Auth section of their Settings module.
Note
If a user has already created OTPs and at a later point the Admin has disabled OTP for that user, the user can still use the existing OTPs. To prevent this behaviour (and forbid the user to use the old OTPs), the user’s OTP codes must be removed from the Carbonio Admin Panel.
Two-Factor authenticator setup enforcement
This section allows administrators to configure remote self-enrollment for two-factor authentication (2FA). Users who have not yet configured 2FA can be allowed to enroll their one-time password (OTP) even when connecting from an untrusted network, such as a home or public Internet connection.
Alternatively, you can configure the same settings at the Class of Service (CoS) level by navigating to Class of Service → Details → Features.
To enable remote self-enrollment:
Enable Allow users to configure 2FA from untrusted networks.
Configure the Grace Period by selecting an expiration date.
Save the changes.
Until the configured expiration date is reached, users connecting from an untrusted network can authenticate using their username and password. Before completing the login process, they are prompted to configure their OTP through the enrollment wizard.
After the grace period expires, users who have not completed the enrollment can no longer configure 2FA remotely and must contact an administrator to complete the setup.
Backup
A switch allows to toggle the user’s ability to recover e-mail that have already been deleted from the Trash Bin, but are still present in the Backup
Password
A policy can set to force the user to select a secure password and the type of characters required for the password.
The Forgotten password feature, if enabled, allows a user to receive a token, to temporarily access the webmail, to the recovery address specified in the textfield next to the option. It also provides the user a new option in the , namely the ability to change the recovery address.
See also
The Password recovery procedure is described in section Lost Password.
The Failed login policy determines how the system behaves when a user fails too many consecutive logins.
Administration
You can choose if the user can play one or more Administration Components in Carbonio.
By toggling the Global Administration switch you can promote or demote the user to Global Administrator or vice versa. In this case, the Delegated Administration switch will disappear, because the Global Administrator already has all the Rights.
If you toggle the Delegated Administration switch. you can then select one domain and assign to the user one of the available Components from the drop downs. Multiple Components can be assigned, even on the same domain: for example, a user can be a HelpDesk Administrator and a Group Administrator.
Delegates
In this tab it is possible to define which other accounts or groups have access to the account and which permissions (“Rights”) are granted. The first setting allow to define whether to save or not a copy of the sent messages and where: only in delegated account’s folder or also in the delegate’s folder. To add delegation Rights to an account, please refer to the dedicated section, Create a Shared Account.