Node.ms

🔐
Delinea Secret Server Training Documentation
LIVE TRAINING MODULE

Creating a Vendor Local Account
in Delinea Directory

Step-by-step interactive guide for provisioning vendor access accounts in Secret Server using Delinea Directory with the Vendor account type designation.

Platform: Secret Server
Role: Administrator
Est. Time: 5–8 min
Difficulty: Beginner
🎉

Training Complete!

You've successfully learned how to create a Vendor Local Account in Delinea Directory and send an invite via Secret Server.

  • Navigated to Admin → User Management
  • Created a new local user in Delinea Directory
  • Selected Vendor as the account type
  • Configured access groups and expiration
  • Saved the account and sent the vendor invite
01
Navigation
Access User Management in Secret Server

Begin by navigating to the User Management section within the Secret Server administration console. You must have Administrator privileges to create new accounts.

ℹ️
Ensure you are logged in with an Administrator or User Administrator role. Regular users cannot create accounts.
https://yourcompany.delinea.app/
📊 Dashboard
🔑 Secrets
⚙️ Admin
📋 Reports
Admin Panel — Select User Management from the left-side menu under the Administration section.
  • 1
    Log in to your Secret Server instance with admin credentials.
  • 2
    Click Admin in the top navigation bar.
  • 3
    In the left sidebar under Administration, select User Management.
  • 4
    The User Management page will display all current users and groups.
02
Initiation
Click "+ Create User" to Begin

On the User Management page, locate the button to create a new user. This opens the user creation form where you'll configure the vendor's local account.

https://yourcompany.delinea.app/admin/user-management
User Management
Filter Users
+ Create User
UsernameDisplay NameTypeStatus
admin.userSystem AdminLocal● Active
svc.accountService AccountLocal● Active
  • 1
    On the User Management page, locate the + Create User button in the top-right area.
  • 2
    Click it — a new user creation dialog or page will open.
  • 3
    You will see a form with fields for user details and directory selection.
03
Directory Selection
Select "Delinea Directory" as the Directory

In the user creation form, the first critical step is selecting the correct directory. You must choose Delinea Directory to create a managed local account within Secret Server's built-in identity store.

⚠️
Do not select Active Directory or LDAP for vendor accounts. Vendor local accounts must be created under Delinea Directory to ensure proper access controls and expiration policies.
https://yourcompany.delinea.app/admin/user-management/new
New User — Directory Selection
* Directory
Delinea Directory
🗂 DIRECTORY OPTIONS — SELECT THE CORRECT ONE:
Active Directory — For domain-joined accounts (corp users)
LDAP — For existing directory service users
Delinea Directory ✓ — Local Identity Store for vendor accounts
Azure AD — For cloud-only Microsoft identities
  • 1
    Find the Directory dropdown at the top of the user creation form.
  • 2
    Click the dropdown and scroll to find Delinea Directory.
  • 3
    Select Delinea Directory — the form will update to show local account fields.
04
User Details
Enter Vendor User Information

Fill in the vendor's identity details. Use a consistent naming convention for vendor accounts — many organizations use a prefix like vnd- or vendor- to clearly distinguish vendor accounts from internal users.

💡
Use a naming convention such as vnd-firstname.lastname or vendor-companyname to make vendor accounts easily identifiable in audit logs and reports.
https://yourcompany.delinea.app/admin/user-management/new
New User — Basic Information
Filled / Active
Empty
Required
* Username
vnd-john.smith
* Display Name
John Smith (Vendor)
* Email Address
j.smith@vendorco.com
Phone Number
Optional...
* Password
••••••••••••
* Confirm Password
••••••••••••
Company / Vendor Name
VendorCo Solutions Inc.
  • 1
    Username: Enter a unique username following your naming convention (e.g., vnd-john.smith).
  • 2
    Display Name: Use the vendor's full name and optionally append (Vendor) for clarity.
  • 3
    Email Address: Enter the vendor's corporate email — this is where the invite will be sent.
  • 4
    Password: Set an initial password or enable "Require Password Change at Next Login."
05
⭐ Critical Step
Set Account Type to "Vendor"

This is the most critical step. You must set the Account Type (or User Type) field to Vendor. This classification enables vendor-specific policies, limited access scopes, and time-bound invitation workflows.

Selecting Vendor as the account type automatically applies your organization's vendor access policies, including session monitoring, expiration dates, and restricted secret access.
https://yourcompany.delinea.app/admin/user-management/new
New User — Account Classification
* Account Type / User Type
🏷️ Vendor
Account Status
● Enabled
Vendor account type selected — vendor access policies will be applied automatically.
⚠️
If you do not see a Vendor option in the Account Type dropdown, contact your Secret Server administrator — the Vendor account type must be configured in the system settings before it appears as an option.
  • 1
    Scroll to the Account Classification or User Type section of the form.
  • 2
    Click the Account Type dropdown field.
  • 3
    From the list, select Vendor — it may show as "Vendor" or "External Vendor."
  • 4
    Confirm the field shows Vendor and that the vendor policy notice appears below it.
06
Access Control
Configure Access Groups & Expiration

Set access group membership and configure an account expiration date. Vendor accounts should always have a defined expiration — this enforces least-privilege access and ensures accounts are not left open indefinitely.

https://yourcompany.delinea.app/admin/user-management/new
New User — Access & Expiration
Group Membership
Vendor-ReadOnly × SecretViewer-Vendors × + Add group...
* Account Expiration Date
📅 2026-06-30
Require Password Change
☑ Yes — on first login
Access Restrictions
IP Restriction: None  |  MFA: Required
  • 1
    Under Group Membership, add the vendor to relevant restricted groups (e.g., Vendor-ReadOnly, SecretViewer-Vendors).
  • 2
    Set an Account Expiration Date — best practice is the end of the vendor's contract or project timeline.
  • 3
    Enable Require Password Change on first login to ensure the vendor sets their own secure password.
  • 4
    Optionally configure MFA (Multifactor Authentication) — strongly recommended for vendor accounts.
  • 5
    Set IP restrictions if the vendor will only connect from known IP ranges.
🛡️
Security best practice: Vendor accounts should follow Least Privilege — only assign access to the secrets and folders the vendor specifically needs for their engagement.
07
Finalize
Save Account & Send Vendor Invite

Review all details, save the account, and send the invite email to the vendor. The invitation email will contain login instructions and a link for the vendor to activate their account.

https://yourcompany.delinea.app/admin/user-management/new
Review Summary
Directory
Delinea Directory
Username
vnd-john.smith
Email
j.smith@vendorco.com
Account Type
Vendor ✓
Expiration
2026-06-30
Groups
Vendor-ReadOnly, SecretViewer
Invite Options
Send Welcome / Invite Email to vendor
Require password set on first login
Cancel
💾 Save User & Send Invite
  • 1
    Review the summary panel — verify that Account Type = Vendor and the directory is Delinea Directory.
  • 2
    Check the "Send Welcome / Invite Email" option is selected. This sends the vendor an email with login instructions.
  • 3
    Click Save User & Send Invite (or Create User depending on your version).
  • 4
    Secret Server will create the account and send an activation email to the vendor's email address.
  • 5
    The vendor will receive an email with a link to set their password and access the platform.
🎉
After saving, verify the new account appears in the User Management list with the Vendor type badge and the correct expiration date. The vendor invite email should arrive within a few minutes.