🔐
Delinea Secret Server Training Documentation
LIVE TRAINING MODULE

Creating a Vendor Local Account
in Delinea Directory

Step-by-step interactive guide for provisioning vendor access accounts in Secret Server using Delinea Directory with the Vendor account type designation.

Platform: Secret Server
Role: Administrator
Est. Time: 5–8 min
Difficulty: Beginner
🎉

Training Complete!

You've successfully learned how to create a Vendor Local Account in Delinea Directory and send an invite via Secret Server.

  • Navigated to Admin → User Management
  • Created a new local user in Delinea Directory
  • Selected Vendor as the account type
  • Configured access groups and expiration
  • Saved the account and sent the vendor invite
01
Navigation
Access User Management in Secret Server
â€ē

Begin by navigating to the User Management section within the Secret Server administration console. You must have Administrator privileges to create new accounts.

â„šī¸
Ensure you are logged in with an Administrator or User Administrator role. Regular users cannot create accounts.
https://yourcompany.delinea.app/
📊 Dashboard
🔑 Secrets
âš™ī¸ Admin
📋 Reports
Admin Panel — Select User Management from the left-side menu under the Administration section.
  • 1
    Log in to your Secret Server instance with admin credentials.
  • 2
    Click Admin in the top navigation bar.
  • 3
    In the left sidebar under Administration, select User Management.
  • 4
    The User Management page will display all current users and groups.
02
Initiation
Click "+ Create User" to Begin
â€ē

On the User Management page, locate the button to create a new user. This opens the user creation form where you'll configure the vendor's local account.

https://yourcompany.delinea.app/admin/user-management
User Management
Filter Users
+ Create User
UsernameDisplay NameTypeStatus
admin.userSystem AdminLocal● Active
svc.accountService AccountLocal● Active
  • 1
    On the User Management page, locate the + Create User button in the top-right area.
  • 2
    Click it — a new user creation dialog or page will open.
  • 3
    You will see a form with fields for user details and directory selection.
03
Directory Selection
Select "Delinea Directory" as the Directory
â€ē

In the user creation form, the first critical step is selecting the correct directory. You must choose Delinea Directory to create a managed local account within Secret Server's built-in identity store.

âš ī¸
Do not select Active Directory or LDAP for vendor accounts. Vendor local accounts must be created under Delinea Directory to ensure proper access controls and expiration policies.
https://yourcompany.delinea.app/admin/user-management/new
New User — Directory Selection
* Directory
Delinea Directory â–ŧ
🗂 DIRECTORY OPTIONS — SELECT THE CORRECT ONE:
Active Directory — For domain-joined accounts (corp users)
LDAP — For existing directory service users
Delinea Directory ✓ — Local Identity Store for vendor accounts
Azure AD — For cloud-only Microsoft identities
  • 1
    Find the Directory dropdown at the top of the user creation form.
  • 2
    Click the dropdown and scroll to find Delinea Directory.
  • 3
    Select Delinea Directory — the form will update to show local account fields.
04
User Details
Enter Vendor User Information
â€ē

Fill in the vendor's identity details. Use a consistent naming convention for vendor accounts — many organizations use a prefix like vnd- or vendor- to clearly distinguish vendor accounts from internal users.

💡
Use a naming convention such as vnd-firstname.lastname or vendor-companyname to make vendor accounts easily identifiable in audit logs and reports.
https://yourcompany.delinea.app/admin/user-management/new
New User — Basic Information
Filled / Active
Empty
Required
* Username
vnd-john.smith
* Display Name
John Smith (Vendor)
* Email Address
j.smith@vendorco.com
Phone Number
Optional...
* Password
â€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸ
* Confirm Password
â€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸâ€ĸ
Company / Vendor Name
VendorCo Solutions Inc.
  • 1
    Username: Enter a unique username following your naming convention (e.g., vnd-john.smith).
  • 2
    Display Name: Use the vendor's full name and optionally append (Vendor) for clarity.
  • 3
    Email Address: Enter the vendor's corporate email — this is where the invite will be sent.
  • 4
    Password: Set an initial password or enable "Require Password Change at Next Login."
05
⭐ Critical Step
Set Account Type to "Vendor"
â€ē

This is the most critical step. You must set the Account Type (or User Type) field to Vendor. This classification enables vendor-specific policies, limited access scopes, and time-bound invitation workflows.

✅
Selecting Vendor as the account type automatically applies your organization's vendor access policies, including session monitoring, expiration dates, and restricted secret access.
https://yourcompany.delinea.app/admin/user-management/new
New User — Account Classification
* Account Type / User Type
đŸˇī¸ Vendor â–ŧ
Account Status
● Enabled
Vendor account type selected — vendor access policies will be applied automatically.
âš ī¸
If you do not see a Vendor option in the Account Type dropdown, contact your Secret Server administrator — the Vendor account type must be configured in the system settings before it appears as an option.
  • 1
    Scroll to the Account Classification or User Type section of the form.
  • 2
    Click the Account Type dropdown field.
  • 3
    From the list, select Vendor — it may show as "Vendor" or "External Vendor."
  • 4
    Confirm the field shows Vendor and that the vendor policy notice appears below it.
06
Access Control
Configure Access Groups & Expiration
â€ē

Set access group membership and configure an account expiration date. Vendor accounts should always have a defined expiration — this enforces least-privilege access and ensures accounts are not left open indefinitely.

https://yourcompany.delinea.app/admin/user-management/new
New User — Access & Expiration
Group Membership
Vendor-ReadOnly × SecretViewer-Vendors × + Add group...
* Account Expiration Date
📅 2026-06-30
Require Password Change
☑ Yes — on first login
Access Restrictions
IP Restriction: None  |  MFA: Required
  • 1
    Under Group Membership, add the vendor to relevant restricted groups (e.g., Vendor-ReadOnly, SecretViewer-Vendors).
  • 2
    Set an Account Expiration Date — best practice is the end of the vendor's contract or project timeline.
  • 3
    Enable Require Password Change on first login to ensure the vendor sets their own secure password.
  • 4
    Optionally configure MFA (Multifactor Authentication) — strongly recommended for vendor accounts.
  • 5
    Set IP restrictions if the vendor will only connect from known IP ranges.
đŸ›Ąī¸
Security best practice: Vendor accounts should follow Least Privilege — only assign access to the secrets and folders the vendor specifically needs for their engagement.
07
Finalize
Save Account & Send Vendor Invite
â€ē

Review all details, save the account, and send the invite email to the vendor. The invitation email will contain login instructions and a link for the vendor to activate their account.

https://yourcompany.delinea.app/admin/user-management/new
Review Summary
Directory
Delinea Directory
Username
vnd-john.smith
Email
j.smith@vendorco.com
Account Type
Vendor ✓
Expiration
2026-06-30
Groups
Vendor-ReadOnly, SecretViewer
Invite Options
☑ Send Welcome / Invite Email to vendor
☑ Require password set on first login
Cancel
💾 Save User & Send Invite
  • 1
    Review the summary panel — verify that Account Type = Vendor and the directory is Delinea Directory.
  • 2
    Check the "Send Welcome / Invite Email" option is selected. This sends the vendor an email with login instructions.
  • 3
    Click Save User & Send Invite (or Create User depending on your version).
  • 4
    Secret Server will create the account and send an activation email to the vendor's email address.
  • 5
    The vendor will receive an email with a link to set their password and access the platform.
🎉
After saving, verify the new account appears in the User Management list with the Vendor type badge and the correct expiration date. The vendor invite email should arrive within a few minutes.