Skip to main content

Internal system

NIM internal access guide

The Internal system stores the users, groups, and memberships that NIM uses for its own access and App experiences.

The Internal system is a built-in target system. Unlike an external connector, it does not connect to a third-party application. Its users and groups are commonly used to control access to Apps and other NIM experiences.

How internal identities workDirect link to How internal identities work

Internal dataPurpose
UsersNIM-managed accounts that can authenticate locally when local authentication is used.
Groups and membershipsMembership data that can support access control, including access to Apps.

Disabled internal user accounts cannot sign in. Do not directly modify the Internal system database; use NIM configuration, mappings, jobs, or the supported management experience instead.

Internal user fieldsDirect link to Internal user fields

View these columns under Systems > internal > users > Columns.

FieldPurpose
IDThe identifier for the Internal user, automatically generated by NIM. Use it when updating an existing Internal user.
NameThe user's username.
EmailThe user's email address.
DisplayNameThe name displayed for the user.
ExternalIDAn identifier used to relate the Internal user to a user in a connected directory system through an inter-system relation.
EnabledDetermines whether the account can sign in to NIM. Disabled accounts cannot sign in.
DescriptionA description of the account.
AuthMethodRestricts the authentication method for the user when defined. When undefined, any authentication method configured in NIM can be used. See the rules below.
ChangePasswordAtLogonDetermines whether local authentication requires the user to change their password at sign-in. This applies to local authentication.
Relate the directory identityMap the connected directory user's identifier to ExternalID, then configure an inter-system relation to match the records. ID identifies the Internal user; ExternalID links that user to the directory identity.

Authentication and accessDirect link to Authentication and access

NIM can authenticate users through local accounts or external identity providers. Choose the approach that matches your organization’s access and lifecycle requirements.

Authentication approachWhen it fitsConfiguration
Local authenticationNIM-managed accounts are appropriate for the users who need access.Create and maintain Internal users and their credentials.
LDAPYour organization manages user identity through LDAP.Configure LDAP
SAML single sign-onYour organization uses an SSO identity provider.Configure SAML

AuthMethod rulesDirect link to AuthMethod rules

AuthMethod controls which authentication method an Internal user can use. It does not configure an identity provider or grant access to an App.

AuthMethod valueSign-in behavior
UndefinedAny authentication method configured in NIM can be used.
saml<configuration name>Only the named SAML configuration can be used. For example, a SAML configuration named Entra uses samlEntra.
LDAP configuration nameUses the named LDAP configuration. For example, a configuration named CorporateDirectory uses CorporateDirectory. The value is the configuration name; use LDAP only if that is the configuration's actual name.

For LDAP, also set ExternalID to the connected directory user's identifier and configure the inter-system relation that links the Internal and directory user records. See Configure LDAP and Configure SAML for provider setup.

Account recoveryDirect link to Account recovery

Users can use the Forgot My Password experience when their internal user record has a valid email address. Administrators can update user data through mappings or App actions. If all administrator access is lost, contact Tools4ever Support.

tip

In NIM log files, the Internal system may be called the Authorization system.

Manage internal users manually (optional)Direct link to Manage internal users manually (optional)

The optional NIM Account Management app provides a manual management experience for Internal users and groups. Administrators can edit user profiles, reset passwords, clear MFA status, enable or disable accounts, and manage group access.

Install it when you need manual account administration. The Internal system and the provisioning workflow below can be used without this app.

The wizard follows the app's README installation instructions.

Prepare the app filesDirect link to Prepare the app files

  1. Confirm the prerequisite Standard Item Library is available in your NIM environment.
  2. Download app.json from the app repository. Save the JSON file locally.
Step 1 of 4

Automate internal user provisioningDirect link to Automate internal user provisioning

Use filters, mappings, and scheduled jobs to automate repeatable Internal user updates from source data. The workflow below shows how to configure, test, and schedule an update.

Create the source filterDirect link to Create the source filter

  1. Open Processing > Filters and select Add.
  2. Give the filter a descriptive name, such as internal_users_password_reset.
  3. Choose internal.users as the Start table.
  4. Run the filter to review the current internal-user records.
  5. Add an expression that limits the result to the users you intend to update, then save the filter.

Check: review the results before saving. The filter should return only the intended users.

Step 1 of 3

Next stepsDirect link to Next steps