Download Reportworq

This is the archived documentation for Reportworq 5. It is kept for reference and is no longer updated.

Go to the Reportworq 6 documentation

Overview#

All users who log in to Reportworq require authentication credentials and licenses. By default, Reportworq uses its native authentication provider. Alternatively, you can configure Reportworq to use Microsoft Entra ID (Azure Active Directory), Google Authenticator, or Custom OpenID Connect (OIDC) authentication.

Users who do not need to log in to Reportworq, such as consumers of distributed reports, do not require licenses or authentication credentials.

If your administrator account is locked out or you forget the password, you can regain control of Reportworq using local administrative control.

This article includes the following major topics:

Note: Reportworq uses AES encryption to store passwords and connection strings at rest.

To access the Authentication interface:

Tap or click the image to view it full screen

Configuring an Authentication Provider#

By default, Reportworq uses its native authentication provider. Alternatively, you can configure Reportworq to use Microsoft Entra ID (Azure Active Directory), Google Authenticator, or Custom OpenID Connect (OIDC). If you switch authentication providers, all existing Reportworq accounts remain but their permissions are removed.

Using Security Claims to Manage Group Membership#

Information in this section applies to non-native authentication providers only.

Reportworq authentication and licensing is based on user accounts, groups, workspaces, and entitlements (licenses). Entitlements can be assigned directly, or via group membership. If you use a non-native authentication provider, you can choose to manage group memberships based on roles assigned in the authentication provider interface.

To manage group memberships based on authentication provider roles:

  1. Create a set of enterprise roles / app roles, complete with security claims. Each role will effectively identify a group of users that require access to a common set of Reportworq features.
  2. Assign roles to users as required. Each user may have any number of roles. When you later create accounts in Reportworq, they are automatically mapped to users from the authentication provider based on matching email addresses. Each user's security claims are automatically propagated to their Reportworq account. Tip: If you manage groups based on roles, a Reportworq account's entitlements do not consume licenses until the first time the user logs in.
  3. In the Reportworq authentication interface, create groups based on security claims. User accounts that possess security claims are added to groups with matching claims. For detailed steps, see Creating and Configuring Groups.
  4. To add or remove an individual group member, edit their user account in the authentication provider to add or remove them from roles. Tip: Changes made in the authentication provider interface are not automatically relayed to Reportworq. After you remove a role from a user, any associated Reportworq licenses are not released for reassignment until the user logs in. To release the licenses immediately, select the account in the Reportworq authentication interface and then clear the Last Claims box. The licence(s) are released, and the user must log in to Reportworq again before they can use any licensed features.

To switch authentication providers:

  1. At the top of the Authentication interface, select the Authentication Provider button. The Advanced Options pane appears.
  2. Select the desired Provider. The configuration interface for the selected provider appears.
  3. If you selected Native authentication:
  1. If you selected authentication by Microsoft Entra ID (Azure Active Directory):
  1. If you selected Google (Google Authenticator):
  1. If you selected Custom OIDC authentication:

Managing User Accounts and Assigning Licenses#

Reportworq authentication and licensing is based on Accounts, Groups, Entitlements, and Workspaces:

The tree on the left side of the authentication interface has four nodes: Accounts, Groups, Entitlements, and Workspaces.

Tap or click the image to view it full screen

To provide flexibility and ease-of-use, the Reportworq authentication interface allows you to edit settings from multiple perspectives. You can expand a node and then select an item to access that item's properties:

Tip: Use the Search box above the tree to quickly find specific items.

This remainder of this section includes the following topics:

Creating and Configuring Accounts#

Each user account is based on an email address in your organization. After you create an account, you can grant it entitlements and add it to groups and workspaces.

To create an account:

  1. Select New Account.
  2. Enter the email address for the account, and then select OK. Note: Reportworq does not create email addresses. They must already exist in your organization. The new account appears in the Accounts node of the authentication tree.

To configure account properties:

  1. In the authentication tree, expand the Accounts node and then select the account you want to configure. Account properties appear. The figure below is based on native authentication.
  2. Review and configure account properties as required:
  1. If you want to force a reset of the account password, select Reset Password (available for native authentication only). The account user is prompted to select a new password the next time they attempt to log in. Tip: If a user forgets their password, they can select Forgot Password from the login dialog to request a password reset. The user is then prompted to provide a new password.
  2. If you want to delete the account, select Delete Account, and then confirm the deletion. IMPORTANT: Deleted accounts cannot be recovered.
  3. To make the account unavailable for use, clear the Account Enabled checkbox. All account properties are hidden except the Name and Email. All the account's entitlements are suspended, and those licenses are available for use by other accounts. The account entry in the authentication tree turns red. If you want to re-enable the account, select the Account Enabled checkbox. Tip: When you create an account, it is enabled by default.

Creating and Configuring Groups#

You can create groups of user accounts and grant them entitlements and/or workspace accesses. An account can belong to any number of groups.

To create a group:

  1. Select New Group.
  2. Enter a name for the group, and then select OK. The new group appears in the Groups node of the authentication tree.

To configure group properties:

  1. In the authentication tree, expand the Groups node and then select the group you want to configure. Group properties appear. The figure below is based on native authentication.
  2. Review and configure group properties as required:

Entitlements Granted -- A list of Reportworq licenses granted to the group. All group members inherit these entitlements. Each group must have at least one entitlement.

Configuring Entitlements#

Entitlements are licenses to use specific sets of Reportworq features. You can grant entitlements directly to accounts, or to groups. If an entitlement is granted to an account through multiple means, only one license for that entitlement is consumed.

To manage entitlements:

Creating and Configuring Workspaces#

Workspaces are segregated working environments within Reportworq. You can grant workspace access to accounts and groups. Each account must have access to at least one workspace, granted either directly or via group membership. System Administrators automatically have access to all workspaces.

To create, rename, or delete a workspace:

  1. At the top of the authentication interface, select the Workspaces button. The Advanced Options pane appears and displays a list of workspaces.
  2. If you want to create a new workspace, select the Create a new Workspace button , provide a name for the workspace, and then select OK. The new workspace appears on the list.
  3. If you want to rename a workspace, select the pencil icon beside the workspace name, provide a new name for the workspace, and then select OK.
  4. If you want to delete a workspace, select the trashcan icon beside the workspace name, and then select OK to confirm the deletion.

To manage workspace access:

  1. In the authentication tree, expand the Workspaces node and then select the workspace you want to configure. Lists of groups and accounts that have access to the workspace appear.
  2. Review and edit the lists as required:

Importing and Exporting Authentication Data#

You can export account properties as an Excel (.xlsx) file, which you can edit and later import. For each user account, the file includes columns for the account name, email address, status (enabled or disabled), groups, entitlements, and workspaces.

Notes about editing account properties in Excel:

To export account properties:

To import account properties:

  1. Select Import.
  2. Browse to select the account properties file (typically named accounts.xlsx), and then select OK. The account properties are imported. Edited account data is updated, and new accounts are added. Accounts are never deleted because of importing account properties.

Local Administrative Control#

You can access select administrative controls locally on the Reportworq server. No password is required for local access.

These local controls enable you to:

To access Reportworq administrative settings locally:

  1. On the computer where Reportworq is installed, use a web browser to navigate to the Reportworq login dialog via the localhost URL. For example, the default URL is http://localhost:8300 or https://localhost:8300.
  2. In the lower right corner, locate the Administration Settings icon. If there is no icon, your Reportworq version was released prior to v5.0.0.69 and local access to administrative controls is not available. If you have lost administrative control of Reportworq, see Regaining Administrative Control for Versions Prior to v5.0.0.69.
  3. Select the Administration Settings icon. Configuration settings appear, including Web Server options, Backup options, and Logging. For more information, see Configuration.
  4. If you want to configure Authentication settings, select Authentication from the Administration menu. Authentication settings appear. For more information about these settings, see Authentication.
  5. If you want to upgrade Reportworq to a different version, select Software Versions from the Administration menu. Software version settings appear. For more information about these settings, see Upgrading Reportworq.

Regaining Administrative Control for Versions Prior to v5.0.0.69#

If your Reportworq version was released prior to v5.0.0.69, you can regain administrative control but all configured user accounts will be deleted and the authentication provider will revert to Native mode.

IMPORTANT: Do this only as a last resort if none of the System Administration passwords are known.

To regain administrative control for Reportworq versions prior to v5.0.0.69:

Feedback on this page

Comments, questions, requests, or something missing or unclear? Email us - the page you are on is filled in for you.

Email feedback on this page

Or write to support@reportworq.com directly.