# Managing users and user permissions

> For Persona organization admins: invite and deactivate users, assign roles to grant permissions, and manage sign-in with SSO and two-factor authentication.

Source: https://help.withpersona.com/articles/5isJzuUdTmFWiLehSDugUI/
Section: Admin > Team and permissions > Key Concepts

## Overview

This guide gives an overview of how to manage users and user permissions in your Persona organization. This guide is written for people who are considered "administrators" of the Persona organization.

## Background

- Read [Roles and permissions overview](https://help.withpersona.com/articles/Ge16TE6VaYZGWVNe2b9cx/). We'll refer to these concepts below.

### Prerequisites

- In order to manage users and their permissions, you must be assigned the permissions to edit users and roles in your organization.

## Create and manage users

As people join or leave your organization, you will need to invite new users and deactivate users who should no longer be able to access the Persona dashboard. These guides explain how:

- [Add a new user](https://help.withpersona.com/articles/745gNyiVwR8ZWm3qTjLngm/)
- [Deactivate a user](https://help.withpersona.com/articles/eaAHaSzMgxBkmP8PcLyZL/)
- [Help user sign in after they lose 2FA method](https://help.withpersona.com/articles/7y6JQx11FvY09pukiyYXQb/)

## Create and manage roles

To grant permissions to users, you assign them one or more roles that have the permissions you want to grant. See these guides for detailed instructions:

- [Create, edit, or deactivate a role](https://help.withpersona.com/articles/1tDmKHklmmR6olOhaWAPNI/)
- [Edit a user’s role](https://help.withpersona.com/articles/63yKrErUY6LfQyPzjM7Uhe/)

## Manage user sign in

Persona offers Single Sign On (SSO) and two-factor authentication (2FA).

### Single Sign On (SSO)

SSO can help you more easily manage many users.

To enable SSO, navigate to **[Organization](https://app.withpersona.com/dashboard/organization) > Authentication**, and under **Single sign-on** click **Manage**. For additional instructions, see:

- [Persona dashboard: SAML-based single sign-on (SSO) with Okta](https://help.withpersona.com/articles/3A0ZoW5ozu1k17n7bOrVuE/)
- [Persona Dashboard: Setting up Google SSO](https://help.withpersona.com/articles/2sRyMDPo1J0YUPPjNA1TMI/)

### Two-factor authentication (2FA)

2FA adds an extra layer of security to user sign ins. For more details, see [Persona Dashboard: two-factor authentication (2FA)](https://help.withpersona.com/articles/2FtrbknhJ3rDsMlWaEag8e/).

#### Available 2FA methods

Persona supports email, SMS, and applications that produce a one-time code (e.g. [Authy](https://authy.com/), [1Password](https://1password.com/)). As an admin, you can choose which of these methods to allow.

#### User preferences

Each individual user can opt into 2FA by visiting the [Security](https://withpersona.com/dashboard/user/profile/security) section of their [Profile](https://withpersona.com/dashboard/user/profile).

#### Require 2FA

As an admin, you have the option to enforce 2FA for all users for their organization.

Note that once enforced, any user who does not have a 2FA method configured will be locked out of their account.

#### Help a user regain access

A user may lose access to their Persona account, if they did not have a 2FA method configured before you required 2FA, or if they lose access to their 2FA method (e.g. their phone or email).

To help them regain access, you can issue a user a one time recovery code. See: [Help user sign in after they lose 2FA method](https://help.withpersona.com/articles/7y6JQx11FvY09pukiyYXQb/)
