Related topics

Logon Setup

Logon Maintenance

The Master user, HR Administrator, Payroll Administrator, and Benefit Administrator can use the Logon Maintenance page to maintain employee logons and access to HRMS Employee Self Service, including:

  • Viewing an employee's username
  • Reviewing an employee's logon history
  • Enabling or disabling an employee's access to the system (logon status)
  • Resetting an employee's password
  • Deleting a logon to free up an employee license
  • Clear Trusted Devices For These Employees when Allow Trusted Devices is enabled
  • Export the current results when searching

The Master user can manage logons for all employees in all companies in your HRMS Employee Self Service system. The HR, Payroll, and Benefit Administrators can manage logons for only those employees in the employers to which their administrator role has access. For information on administrator role access, see Assigning administrator roles.

Logons and licenses

Each employee logon (username and password) counts as one employee license, regardless if the logon status (Active or Locked). The number of employee licenses is determined by the Install code used at installation.

When all employee licenses for your system are used, the next employee who tries to create a new logon receives a message that the number of user licenses has been met and to contact their Human Resources department for assistance.

To manage an employee's logon and status

  1. Log on to HRMS Employee Self Service as the Master user or an administrator.
  2. On the Administrator menu, select System Settings > Logon Maintenance
    or on the System Administrator menu, select Roles and Logon > Logon Maintenance.
  3. On the Logon Maintenance page, search for the employee whose logon information you want to maintain by entering the search criteria and clicking Go.
  4. Note: The Additional Authentication search option lets you find employees based on the two-factor authentication (2FA) method assigned to their account. To search by authentication methods, select Additional Authentication from the Search drop-down and then select one of the options. Leave the For drop-down blank to return all users with an Employee Self Service account.

  5. In the search results table, click the employee's name.
  6. Tip: Select a column header to reorder the table results by that column. For example, click the Additional Authentication column header to reorganize your results by the Additional Authentication method when there are multiple records in the table results.

  7. The Logon Maintenance detail page displays the following information:

    • The employee's Username if the employee already has a logon. Otherwise, Username displays Not Created.
    • The HRMS User security user account is displayed if the employee has been assigned access to the web version of (Sage HRMS as an administrator.
      • To assign a HRMS User to an employee, select an account from the drop-down.
      • When assigned, the employee will have the same access rights as the Security Group in which the selected account has been assigned.
      • The security access applies only to the web version of Sage HRMS and not HRMS Employee Self Service
      • This field is blank by default.
    • The employee's Account Status, which is either
      • Active, which enables the employee to access the system. (This is the default.)
      • Locked, which locks the person out of the system. They are no longer able to log on to the system or create a new logon. When the employee exceeds the set number of failed attempts to log on (which is set on the Logon Setup page), the employee's logon status is automatically set to Locked.
    • To unlock the logon manually, select Active to re-enable access to the system; (the number of failed logon attempts is set back to zero).

      To temporarily prevent an employee from logging on, manually select Locked.

      Tip: You can have the system automatically unlock logon accounts by specifying the number of minutes for Unlock Users Automatically After__ Minutes on the Logon Setup page. This does not unlock users who you manually lock out (by changing their logon status manually to Locked).

    • The Employee Status is the employee's employment status in your company.
    • The Access Expiration fields are only displayed on the Logon Maintenance detail page when the Terminated status has been selected on the Logon Setup page and the employee you are viewing has an "employment" status of Terminated.
      • The Access Expiration date is initially determined by adding the number of days entered in the Days To Expiration field on the Logon Setup page to the employee's termination date.
      • You can modify the Access Expiration date on a per user account to extend the date or shorten it.
      • Select the Override Access Expiration check-box to enable the Access Expiration calendar field and enter or select the date.
    • The Additional Authentication drop-down displays the authentication method currently assigned to the selected employee.
      • Use this drop-down to assign a specific authentication method to the selected employee if applicable.
      • Changing the authentication method will also clear all previously trusted devices for this employee.
    • See the Logon Setup help topic to learn more.

    • The employee's Logon History, including the date, time, employee status (Sage HRMS) and success status of each logon. The most recent logon attempt is at the top of the list. (The number of historical entries to display is set on the Logon Setup page.)
  1. The Reset Password button will replace the employee's current password with a randomly generated password. For security reasons, instruct the employee to change their password to a strong password the next time they log on. Employees will need to select the Username and Password Help link on the HRMS Employee Self Service login page to reset their password.

    Note: The Reset Password button is disabled when the system is set to use Windows Authentication.

  2. To delete the user who will no longer be using the system, click Delete Login and confirm the deletion.

    Caution! All HRMS Employee Self Service data for that employee is deleted, including their logon information, logon history, and audit trail. If you delete a logon for an employee who is currently logged on to the system, they will receive system errors in their Message Center or as they navigate through pages. In order to access the system again, the employee must create a new username and password.

    Tip: You can delete an employee's logon to free up an employee license; (the deleted logon is no longer counted for employee license purposes). If you want to lock the employee out of the system temporarily, set the Status to Locked instead.

  3. When you are finished, click Save.

    The Logon Maintenance summary page is displayed.

    All settings will apply the next time the selected employee logs on to the system.

    Example: John is currently logged on to the system. If you change his logon Status to Locked, John still has access to his pages until he logs off. However, the next time he tries to log on, he will be locked out.

  4. To remove the Trusted Device cookie for all records in the current results, select the Clear Trusted Devices For These Employees button. Narrow your search before clicking this button if you want to target specific employees or authentication types.
    • These employees will be required to complete the full two-factor authentication process on their next login.

    See Trusted Devices to learn more.

  5. Click the Export button to export the search results from the Logon Maintenance page. A .csv file is generated with these columns:

    • Employee
    • EmployeeStatus
    • AccountStatus
    • Employer
    • EmployeeID
    • AdditionalAuthentication

    Note: Only the columns listed above are included. Other columns available in the results table (such as Username and HRMS User) are not part of the export.

Tip: You can contact Customer Service to purchase additional employee user licenses.