---
title: Editing a user
description: Use the Users page to edit users in the PingOne directory.
component: pingone
page_id: pingone:directory:p1_edituser
canonical_url: https://docs.pingidentity.com/pingone/directory/p1_edituser.html
revdate: May 12, 2025
section_ids:
  editing-a-user-customer: Editing a user - Customer
  steps: Steps
  choose-from: Choose from:
  editing-a-user-workforce: Editing a user - Workforce
  steps-2: Steps
  choose-from-2: Choose from:
---

# Editing a user

Use the **Users** page to edit users in the directory. The fields differ slightly based on your configuration.

* Customer

* Workforce

## Editing a user - Customer

Use the **Users** page to edit users in the directory.

### Steps

1. In the PingOne admin console, go to **Directory > Users** and browse or search for the user you want to edit.

2. Click the user entry to open the user details panel.

3. On the **Profile** tab, enter or edit the user's personal information, contact information, identity information, photo, or preferences.

   |   |                                                                                                                                                                |
   | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | Don't upload photos that contain biometric data or other sensitive personal information. The PingOne directory doesn't support secure file storage for photos. |

4. On the **Groups** tab, enter or edit group membership. Click **[icon: plus, set=fa]Add** to add the user to a group.

   Learn more in [Groups](p1_groups.html).

5. Edit user roles.

   #### Choose from:

   * On the **Roles > Administrator Roles** tab, click the **Delete** **[icon: trash, set=fa]**icon to unassign roles that determine actions admins can take in PingOne. To assign a role, click **Grant Roles**.

   * On the **Roles > Application Roles** tab, click the **Pencil** **[icon: pencil, set=fa]**icon or click **Grant Application Roles** to assign or unassign roles that determine access to features and API resources in applications developed by your organization.

     Learn more in [Managing user roles](p1_manage_user_roles.html).

6. On the **Services > Authentication** tab, enter or edit authentication information.

   |   |                                                                                                                                                                                                                                                                                                             |
   | - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | Unpairing your last device or disabling MFA on your administrator account through the [PingOne Self-Service - MyAccount app](../user_experience/p1_self_service.html) will block your ability to authenticate. You will need another administrator to re-enable your account or assist with device pairing. |

   * For **Multi-factor authentication**, click the toggle to enable or disable MFA.

   * Under **Methods and Devices**:

     * Click a device entry to show the date and time that the device was paired. For mobile devices that have sent logs, this view also displays the date, time, and Support ID of the most recent logs.

     * To unpair a device, click the **More Options (⋮)** icon for the device and then select **Unpair**.

   * Under **Authoritative identity provider**, PingOne shows any configured external identity providers. To change the authoritative identity provider, click the **More Options (⋮)** icon and then select **Edit**.

     Learn more in [Authoritative identity providers](../integrations/p1_authoritative_idps.html).

   * Under **Linked accounts**, PingOne shows any external accounts, such as Google or LinkedIn, that are linked to the user profile. To unlink an external account, click the **More Options (⋮)** icon and then select **Unlink**.

7. On the **Services > Consent** tab, view agreements to which the user has consented.

8. On the **Services > Credentials** tab, if a user has a credential issued to them, view the credential and its status.

   Learn more in [Managing a user's credentials](p1_manage_user_credentials.html)

9. On the **Services > ID Verification** tab (PingOne Verify only), view user ID verification (IDV) results and Identity Assurance (IDA). Learn more about enabling IDA in [Creating a verify policy](../identity_verification_using_pingone_verify/p1_verify_creating_verify_policy.html).

   In the **Identity Assurance Claims** section:

   * Click **Show** to display IDA attributes that were verified during the IDV process and stored per policy configuration.

   * Click **Reset Data** to reset the identity assurance claims for the user.

   In the **Transaction ID** section:

   * Click **View** to view the metadata **Result** for a specific transaction ID.

   * Click **Manually Approve** to approve user ID verification manually.

10. On the **Services > Sync status** tab, view the sync status for any provisioning connections.

    Learn more in [Provisioning](../integrations/p1_provisioning.html).

11. On the **API** tab, view technical information about the user, such as user ID, environment ID, and the URL at which the user data can be found.

## Editing a user - Workforce

Use the **Users** page to edit users in the directory.

|   |                                                                                                        |
| - | ------------------------------------------------------------------------------------------------------ |
|   | If you have a PingID account connected to your environment, the `Username` attribute cannot be edited. |

### Steps

1. In the PingOne admin console, go to **Directory > Users** and browse or search for the user you want to edit.

2. Click the user entry to open the user details panel.

3. On the **Profile** tab, enter or edit the user's personal information, contact information, identity information, photo, or preferences.

   |   |                                                                                                                                                                |
   | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | Don't upload photos that contain biometric data or other sensitive personal information. The PingOne directory doesn't support secure file storage for photos. |

4. On the **Groups** tab, enter or edit group membership. Click **[icon: plus, set=fa]Add** to add the user to a group.

   Learn more in [Groups](p1_groups.html).

5. Edit user roles.

   #### Choose from:

   * On the **Roles > Administrator Roles** tab, click the **Delete** icon to unassign roles that determine actions admins can take in PingOne. To assign a role, click **Grant Roles**.

   * On the **Roles > Application Roles** tab, click the **Pencil** icon or click **Grant Application Roles** to assign or unassign roles that determine access to features and API resources in applications developed by your organization.

   Learn more in [Managing user roles](p1_manage_user_roles.html).

6. In the **Services** list, select **Authentication** and enter or edit authentication information.

   |   |                                                                                                                                                                                                                                               |
   | - | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | Unpairing your last device or disabling multi-factor authentication (MFA) on your administrator account will block your ability to authenticate. You will need another administrator to re-enable your account or assist with device pairing. |

   * For **Multi-factor authentication**, click the toggle to enable or disable MFA.

   * To bypass MFA for single sign-on (SSO), under **Multi-Factor Authentication**, click **Allow MFA bypass** and then in the **Bypass** modal, select the bypass duration and click **Bypass**.

     The bypass time remaining, and a **Resume** link are shown. Click **Resume** to resume MFA for the selected user.

   * In the **Methods and Devices** section:

     * Click a device entry to show the date and time that the device was paired. For mobile devices that have sent logs, this view also displays the date, time, and Support ID of the most recent logs.

     * To unpair a device, click the **More Options (⋮)** icon for the device and then select **Unpair**.

   * Under **Authoritative identity provider**, PingOne shows any configured external identity providers. To change the authoritative identity provider, click the **More Options (⋮)** icon and then select **Edit**.

     Learn more in [Authoritative identity providers](../integrations/p1_authoritative_idps.html).

   * Under **Linked accounts**, PingOne shows any external accounts, such as Google or LinkedIn, that are linked to the user profile. To unlink an external account, click the **More Options (⋮)** icon and then select **Unlink**.

   * Under **Integrations**, select the services that should be enabled for the user. To disable or bypass a service, click the **More Options (⋮)** icon and then select **Disable** or **Bypass**. Bypassing a service suspends the need for a user to authenticate using the secondary authentication method for a specified amount of time.

7. On the **Services > Consent** tab, view PingOne agreements to which the user has consented.

8. On the **Services > ID verification** tab (PingOne Verify only), PingOne shows verification status for the user. View the verification history, reset verification status, or manually approve a user.

   Learn more in [PingOne Verify](../identity_verification_using_pingone_verify/p1_verify_start.html).

9. On the **Services > Sync status** tab, view the sync status for any provisioning connections.

   Learn more in [Provisioning](../integrations/p1_provisioning.html).

10. On the **API** tab, view technical information about the user, such as user ID, environment ID, and the URL for the user's data.
