{"id":253,"date":"2026-04-01T10:05:26","date_gmt":"2026-04-01T09:05:26","guid":{"rendered":"https:\/\/overlaps.co.uk\/docs\/?page_id=253"},"modified":"2026-04-01T10:35:00","modified_gmt":"2026-04-01T09:35:00","slug":"managing-user-self-service-computers","status":"publish","type":"page","link":"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/users-and-groups\/managing-user-self-service-computers\/","title":{"rendered":"Managing User Self Service Computers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Self-Service Computers window allows you to specify one or more computers which the selected user(s) or group(s) will be able to access the Local Administrator password for. This allows for \u201cpower users\u201d to be setup with access to a small number of computers where granting access to an entire Organizational Unit is not desirable.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"748\" height=\"358\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service.jpg\" alt=\"Edit Self-Service User Window\" class=\"wp-image-276\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service.jpg 748w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-300x144.jpg 300w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\" \/><figcaption class=\"wp-element-caption\">Edit Self-Service User Window<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Beside the computer name are two checkboxes which are (from left to right): <strong>Require Justification<\/strong> and <strong>Require Authorisation<\/strong>. These work much the same as regular user permissions where if the first box is checked, the user will be prompted for an explanation of why they&#8217;re accessing the password, and the second will additionally require an Nominated Authoriser to approve or deny the request before the Self-Service user can actually access the password. Only one of these boxes can be checked at a time for each computer.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote has-secondary-background-color has-text-color has-background has-link-color wp-elements-764854f526d856ec0deb051279ad0c62 is-layout-flow wp-block-quote-is-layout-flow\" style=\"color:#ffffff\">\n<p class=\"wp-block-paragraph\"><strong>Warning:<\/strong> When selecting multiple users\/groups and opening this window, all of the Self-Service computers for all of the users will be shown. Saving Changes now will grant access to all of those computers to all of the selected users. For this reason, it is recommended to only edit one user at a time.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"manually-adding-self-service-computers\">Manually Adding Self-Service Computers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To add a computer, start typing its name in the <strong>Computer Name<\/strong> field. You will be presented with a list of similar matching computer names from Active Directory.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"191\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-search.png\" alt=\"Adding a Self-Service Computer using the dropdown menu\" class=\"wp-image-278\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-search.png 400w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-search-300x143.png 300w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption class=\"wp-element-caption\">Adding a Self-Service Computer<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To add one of the displayed computers, simple click its name and it will be added to the list of computers below the computer name box.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"using-active-directorys-managed-by-property\">Using Active Directory&#8217;s &#8220;Managed By&#8221; Property<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An alternative (or addition) to adding the computers one-by-one here is to check one of the <strong>Active Directory \u201cManaged By&#8221;<\/strong> option under the <strong>Managed By<\/strong> tab.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"749\" height=\"382\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by.jpg\" alt=\"Accessing Self-Service devices via the &quot;Managed By&quot; attribute\" class=\"wp-image-279\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by.jpg 749w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by-300x153.jpg 300w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\" \/><figcaption class=\"wp-element-caption\">Self-Service &#8220;Managed By&#8221;<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Selecting either the <strong>Require Authorization for Computers Managed By The User(s)<\/strong>, <strong>Authorisation Not Required<\/strong> or <strong>Justification Required<\/strong> options will, when a user goes to their Self-Service page, also show a list of any computers that the user is marked as the Manager of through Active Directory.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"170\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by-property.png\" alt=\"A Computer Managed by a User in Active Directory\" class=\"wp-image-280\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by-property.png 500w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-managed-by-property-300x102.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption class=\"wp-element-caption\">A Computer Managed by a User in Active Directory<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This can be a quicker way of setting up Self Service if you have already populated this value, or if you are planning to populate it by, for example, exporting the information from SCCM by a script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For information about the Self-Service experience, see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/user-interface\/self-service\/\">Self Service<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"requiring-authorisation\">Requiring Authorisation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For manually added computers, the Require Authorisation checkbox indicates that the user must first submit an Authorisation Request and have it approved before they can view the computer\u2019s password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When using the \u201cManaged By\u201d feature, you can also select whether an Authorisation Request is required or not by selecting the appropriate option.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"entra-self-service\">Entra Self Service<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Entra devices can be added to Self-Service users from the Entra tab. The two options available are:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Allowing users to access any device that they are the &#8220;Owner&#8221; of in Entra.<\/li>\n\n\n\n<li>Manually added devices by name.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If adding a device by name, check its Device ID matches your records as duplicate names are permitted in Entra.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither the Authorisation Request or Justification systems are currently implemented for Entra Self-Service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"authoriser\">Authoriser<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"802\" height=\"504\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-authoriser.jpg\" alt=\"Edit Self-Service Window Authoriser Tab\" class=\"wp-image-281\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-authoriser.jpg 802w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-authoriser-300x189.jpg 300w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-authoriser-768x483.jpg 768w\" sizes=\"auto, (max-width: 802px) 100vw, 802px\" \/><figcaption class=\"wp-element-caption\">Self-Service Authoriser<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To nominate a user or group who can provide or deny authorisation requests generated by a Self Service user you can use one of two methods:<\/p>\n\n\n\n<h3 id=\"authoriser\" class=\"wp-block-heading\">Authoriser<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can add the Authoriser user or group to the Active Directory container permissions (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/container-permissions\/\" data-type=\"page\" data-id=\"66\">Container Permissions<\/a>), and check the option <strong>Authorise Self-Service Access Requests<\/strong>. This will grant the user permission to authorise requests from Self Service users on all computers in this container.<\/p>\n\n\n\n<h3 id=\"selfservice-authoriser\" class=\"wp-block-heading\">Self-Service Authoriser<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Alternatively, you can specify the user\/group in the Self-Service settings dialog as shown above. This will allow the user to authorise Self Service requests only on the computers in this Self-Service setup.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"automatic-expiration\">Automatic Expiration<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"452\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-expiry.jpg\" alt=\"Self-Service Automatic Expiration\" class=\"wp-image-282\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-expiry.jpg 803w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-expiry-300x169.jpg 300w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-users-edit-self-service-expiry-768x432.jpg 768w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><figcaption class=\"wp-element-caption\">Self-Service Automatic Expiration<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to grant temporary Self-Service access then you can specify an expiry date and time. After this time the user will lose access to all of their Self-Service computers listed under the Computers tab. <strong>Note this does not apply to access granted by the Managed By property<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The user is not removed after this expiry date, rather they just lose Self-Service access. This means they can easily be re-activated again at a later date if needed without having to go through the whole setup again.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"moving-computers\">Moving Computers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It is important to note that, for security reasons, if a computer is moved from its Organizational Unit to another, any users with that computer added to their Self Service computer list will lose access to it until it is removed and re-added to their list.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This behaviour can be changed using the <strong>Automatic Self-Service Cleanup Mode<\/strong> setting in you <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/security\/\" data-type=\"link\" data-id=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/security\/\">Security<\/a> settings.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Self-Service Computers window allows you to specify one or more computers which the selected user(s) or group(s) will be able to access the Local Administrator password for. This allows for \u201cpower users\u201d to be setup with access to a small number of computers where granting access to an entire Organizational Unit is not desirable. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":63,"menu_order":500,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-253","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/comments?post=253"}],"version-history":[{"count":2,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/253\/revisions"}],"predecessor-version":[{"id":283,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/253\/revisions\/283"}],"up":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/63"}],"wp:attachment":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/media?parent=253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}