Skip to main content

VPN Users

VPN users are end users who connect to the SecureLink network through VPN client applications. They are managed separately from admin users and do not have access to the management UI.

Navigate to Settings > Users > VPN Users tab to manage VPN client accounts.

Key Concepts

  • VPN users are stored in a separate table from admin users and have a distinct user type (type 3).
  • VPN users can only authenticate through VPN client applications (SecureLink desktop and mobile apps).
  • Each VPN user is assigned to a specific tenant and can only access that tenant's VPN network.
tip

VPN users don't have access to the management UI -- they can only connect via VPN clients. If a user needs to manage infrastructure, create an admin account instead.

User List

The VPN users table displays the following information:

ColumnDescription
NameThe user's display name
EmailThe email address used for VPN authentication
TenantThe tenant this VPN user belongs to
StatusActive or Disabled
DevicesNumber of registered VPN client devices
Last ConnectedTimestamp of the most recent VPN connection

Inviting VPN Users

  1. Click the Invite VPN Users button.
  2. Fill in the invitation form:
    • Email addresses — One or more email addresses (bulk import supported).
    • Device Groups — Select at least one device group (mandatory). The first group becomes the user's primary group, which determines their initial edge connection. Use the star/arrow controls to reorder and set the primary group.
    • Email Template — Optionally select an email template for the invitation.
  3. Click Send Invitations.
  4. Invitation emails are sent with VPN setup instructions and links to download the client app.
Device Groups Required

Every VPN user must be assigned to at least one device group. Device groups determine which edge the user connects to and what access policies apply. See Device Groups for more information.

User Activation

When a user accepts the invitation and verifies their email address via the Email Verification email, the system automatically activates their account. Pending invited users (status=1) transition to active (status=0) on successful email verification.

note

If a VPN user tries to sign in at the web management console (/login), they will see a "Continue on the SecureLink App" screen with download links for the SecureLink VPN client. Web management sessions are not issued for VPN-only users. They must use the SecureLink app to connect.

Filtering by Tenant

Use the Tenant filter dropdown above the user list to display VPN users for a specific organization. This is useful for SuperAdmins managing users across multiple tenants.

Select "All Tenants" to view every VPN user in the platform.

Disabling a VPN User

To revoke a VPN user's access without deleting their account:

  1. Select the user from the list.
  2. Toggle the status to Disabled.
  3. The user's active VPN sessions will be terminated and they will be unable to reconnect.

The account and its associated data are preserved. Re-enable the user at any time by toggling the status back to Active.

note

Deleting a VPN user permanently removes their account and all associated device registrations. Use disable instead of delete if you may need to restore access later.