Error requesting to delete 1 user
Overview
This article explains why you may be unable to delete a user who is part of an Approval Group within PreVeil, and how to resolve the issue while preserving the necessary security controls.
Audience: Organization administrators on Full PreVeil.
Why this happens
The user is a member of an Approval Group.
Resolution steps
Follow these steps in order:
Create a new Approval Group that excludes the user you want to delete, to replace the existing group.
Assign the newly created group to the appropriate roles in the Assignments tab, including Account Recovery (for users who should be covered under account recovery), Data Export, and the optional Admin Management assignment (not required).
Note: When you reassign a recovery group, every member reassigned will need to download a new recovery file.
A recovery file is only valid for a given user key. Reassigning the recovery group causes a rekey of the user key, which means that the previous recovery file no longer works.
That said, the rekey only happens when changing from one group to another, and not when first assigning a recovery group
Have the outgoing Approval Group approve the replacement.
Note: Please proceed to step 4 if the outgoing approval group members are available; if not, then you may request our support team to delete that approval group to release the user(s) that need deletion.)
Once the new group has been assigned to all necessary assignments and the old group is no longer assigned to any roles, you may proceed with deleting the old approval group.
Once the approval group has been deleted, you may then proceed to delete the user(s) who were released from that old approval group.
To create a group:
Click the Admin Console option in the menu bar at the top of the PreVeil browser application, and then select Approval Groups from the left-hand menu.
1. Create a new Approval Group that excludes the user you want to delete.
Click on the plus sign icon under the Manage tab.
Give the group a name, and then type in the email address of the first user you want to add. When the user’s email address shows up in the pre-filled drop-down menu, select it to add the user to the group. Repeat to add at least two more additional users to the group. (Remember that you will need to add at least three users before you can create the group; the Create Approval Group button will remain grayed out until at least three users have been added to the group.)
Once at least three users have been added to the group, click on the Create button.
If you create a group with more than three users, then you will have additional options to select from in the How many approvals are required for recovery drop-down menu for the required number of approvers
You will receive a notification that the group has been created
Assigning an Approval Group
Assign the newly created group to the appropriate roles in the Assignments tab, including Account Recovery (for users who should be covered under account recovery), Data Export, and the optional Admin Management assignment (not required).
Detailed UI steps
Click on the Assign tab in the Approval Group section of the Admin Console.
Click on the Assign button next to either Admin Management or Data Export. For this example we’ll use Data Export.
Select the group that you want to assign to that activity from the drop-down list.
You will see the details about the group you selected. Click Assign to assign the group to the activity.
You will receive a confirmation message that the selected group is now assigned to the activity.
To assign an Approval Group as the Recovery Group for your organization’s users
Select Approval Group from the left-hand menu, then click on the Assign tab.
Click on the Manage Users button.
Click on the checkbox next to the user (or users) you want to assign the Recovery Group to. (You can assign it to more than one user at a time.)
Click on the Set Recovery Group button.
Select the group that you want to assign as the Recovery Group from the drop-down list.
You will see the details about the group you selected. Click Set Recovery Group to assign the group to the users.
You will receive a confirmation that the group will now be assigned as the Recovery Group for the selected user (or users).
Note: The user’s computer needs to be online for the Recovery Group to be successfully assigned. If the user’s device is not online, the Recovery Group will not be assigned to the user’s account. The recovery group will show up in the admin console, but the assignment will be incomplete. If the user’s device doesn’t come online within two weeks of the group being assigned, the assignment will fail, and the group will be removed from the user’s entry in the admin console.
Have the outgoing Approval Group approve the replacement.
The outgoing Approval Group must approve this replacement action before the new group is assigned to the activity.
Two of the approvers will need to open their PreVeil applications at the same time, then click the Settings wheel in the upper-right corner of the application and navigate to the Approvals section to approve the recent request. (Each approver should see a pending badge on the Approvals section)
Once each approver clicks on the Approvals section in the menu, they will see a pending request.
Click on the pending change request, then select the orange Approve button. This will approve the action and assign the new Approval Group to the users.
Once the outgoing Approval Group has accepted the pending change request, the admin can delete the Approval Group and then delete the user(s).
Deleting an Approval Group
Once the new group has been assigned to all necessary assignments and the old group is no longer assigned to any roles, you may proceed with deleting the old approval group.
Note: You will not be able to delete an Approval Group if it is currently assigned to an activity. If this is the case, the Approval Group will need to be replaced with the new approval group before it can be deleted.
To delete an Approval Group:
Please follow the steps below:
Select the checkbox of the group you want to delete, and then click on the trash can icon.
Click Yes to confirm.
You will receive a notification that the group has been deleted.
Deleting a User
Once the approval group has been deleted, you may then proceed to delete the user(s) who were released from that old approval group.
To delete a user:
Click the checkbox next to the name of the user whom you want to delete.
Click on the trash can icon
Click Yes to confirm the deletion of the account.
You’ll receive confirmation that the selected user account has been successfully deleted.
Note: If you need further assistance, please open a ticket with us at preveil.com/support