How Do You Manage User Accounts and Technician Access in ManageEngine ServiceDesk Plus? - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How Do You Manage User Accounts and Technician Access in ManageEngine ServiceDesk Plus?

What Should You Know First?

Here is the short version for busy admins.

  • Two user types exist. ServiceDesk Plus classifies users as requesters, who raise requests, and technicians, who resolve them.
  • Roles control technician access. You assign roles only to technicians, and each role defines what a technician can view, add, edit or delete.
  • Import users in bulk. You can bring in requesters from Active Directory or a CSV file instead of typing them one by one.
  • Convert users when needed. You can change a requester into a technician, and back again, without deleting records.
  • Licences follow technician logins. Removing a technician’s login frees the licence.
  • Menu paths vary. Cloud editions use Setup, while on-premises editions use Admin, so check your version.

Follow the steps below, and you can build a clean, secure user structure in an afternoon.


What Is ManageEngine ServiceDesk Plus and Why Does Access Management Matter?

ManageEngine ServiceDesk Plus – ITSM Software is an IT service management platform. IT teams use it to log incidents, handle service requests, track assets, manage changes and publish knowledge articles. Every one of those activities involves people, so user accounts and technician access sit at the heart of the product.

How Does This Topic Relate to the Software?

ManageEngine ServiceDesk Plus – ITSM Software works only as well as its user setup. If you give every technician full rights, you risk accidental changes and data exposure. If you restrict access too tightly, technicians cannot do their jobs and tickets pile up. Good account management balances both concerns.

The rest of this article shows how to strike that balance. It uses ServiceDesk Plus terminology throughout, and it notes where menu paths differ between editions.

Which Edition Should You Follow?

ManageEngine’s documentation shows two main menu styles. The on-premises help refers to Admin > Users, while the cloud FAQ refers to Setup > Users & Permissions > Users. The steps below use both names where needed. Always confirm labels in your own console, because interface updates can move menus.


What Is the Difference Between Requesters and Technicians?

The ServiceDesk Plus user guide states that the application classifies users as requesters and technicians. This split drives everything else you configure.

Who Are Requesters?

Requesters are the employees or customers who ask for help. They log in to the self-service portal, raise tickets, check status and read knowledge base articles. They do not resolve requests.

Who Are Technicians?

Technicians work the tickets. They accept assignments, update requests, add notes and close issues. Technicians also receive roles that define their permissions. ManageEngine’s documentation notes that you can assign roles only to technicians, not to requesters.

How Do the Two Types Compare?

FeatureRequesterTechnician
Main purposeRaise and track requestsResolve and manage requests
Access pointSelf-service portalTechnician console
Uses rolesNoYes
Counts toward licenceGenerally noYes, when the technician has login access
Typical sourceDirectory import or CSVManual creation or conversion from requester

How Do You Add Requesters to ServiceDesk Plus?

By default, ServiceDesk Plus imports new users as requesters. That default protects you, because nobody gains technician power by accident.

Which Methods Can You Use?

ManageEngine’s user guide lists several ways to add requesters. The table below summarises the main options.

MethodBest forNotes
Manual entryA few usersUse the Add New Requester option
Active Directory importOrganisations with a directoryKeeps accounts aligned with your directory
CSV importBulk lists from HR or other systemsPrepare a clean file first
Dynamic user additionOngoing onboardingUsers log in with domain credentials and the system adds them automatically

ManageEngine’s FAQ explains the dynamic option this way: a user enters a domain username and password, selects the domain and logs in, and the application adds that person as a requester without a separate import.

How Do You Import Requesters Step by Step?

  1. Sign in as an administrator.
  2. Open the requester list under Admin (on-premises) or Setup > Users & Permissions (cloud).
  3. Choose the import option, such as Active Directory or CSV.
  4. Map the fields, for example name, email, department and job title.
  5. Run the import and review the results.
  6. Spot-check several accounts for accuracy.

How Do You Keep Requester Data Clean?

Clean data prevents routing errors later. Standardise department names before import. Remove duplicate entries and inactive employees. Then schedule a regular sync or review, so the list keeps pace with real staffing changes.


How Do You Add and Configure a Technician?

You can create technicians in two ways. You can add a new technician manually, or you can convert an existing requester.

How Do You Add a Technician Manually?

ManageEngine’s technician guide describes the path: open the technician list under Admin > Users > Technicians, and click Add New. Then follow these steps:

  1. Enter the technician’s name, email and employee details.
  2. Set the login details, if the technician needs console access.
  3. Associate the technician with a site, if you use multiple sites.
  4. Assign one or more roles.
  5. Save the record.

The help page notes that a technician not linked to any site defaults to Not in any Site, so set the site deliberately if you segment your operations.

How Do You Convert a Requester to a Technician?

Conversion saves time when you already imported people from a directory. ManageEngine’s FAQ explains that imported users appear under requesters, and you can select Change as Technician next to the person’s name. The edit form then lets you associate sites, assign technician groups and grant access permissions.

The MSP edition adds a detail worth noting. When you convert a requester, the form shows the role SDGuest, and you should replace it with the role that fits the new technician.

How Do You Convert a Technician Back to a Requester?

Open the technician list, select the person and choose Change as Requester. Cloud documentation places this under the Actions menu. Use this option when someone leaves the support team but stays with the company.

What Other Options Appear on the Technician Form?

The technician form also offers API key generation and integrations with other ManageEngine products, according to the help documentation. Generate API keys only for technicians who need them, and treat each key like a password.


How Do Roles Control Technician Access?

Roles form the core of technician access control. Each role bundles permissions, and you assign those bundles to technicians.

What Are Default and Custom Roles?

ManageEngine’s documentation explains that ServiceDesk Plus ships with predefined system roles, and you can also create custom roles with fine-grained access privileges. The user guide describes the path Admin > Roles > Add New Role for on-premises editions. In newer interfaces, the MSP documentation places roles under Admin > Users & Permissions > Roles.

Use default roles as a starting point. Then build custom roles for teams that need something different, for example a read-only role for auditors.

Which Permissions Can You Set?

Role configuration lets you allow or block Add, Edit, Delete and View operations for each module, such as requests, problems, changes and assets. The documentation also lists advanced permissions, for example permission to edit a requester’s name while viewing a request.

One example from ManageEngine shows how modules interact. If a technician has add, edit and delete permission over the assets module, the same operations apply to configuration items in the CMDB.

How Do You Create a Custom Role?

  1. Open the roles page from the admin menu.
  2. Click Add New Role.
  3. Name the role clearly, such as “Tier 1 Support” or “Change Approver.”
  4. Tick the permissions for each module.
  5. Enable advanced permissions only where necessary.
  6. Save the role.
  7. Assign the role to the relevant technicians.

What Is the SDAdmin Role?

Third-party integration guidance mentions a technician with the SDAdmin role for provisioning tasks. Treat this role as a super-user. Limit it to a very small number of trusted people, and create narrower roles for everyone else. One integration vendor even recommends a limited technician role for integrations instead of SDAdmin.


How Do Technician Groups and Sites Narrow Access?

Roles define what a technician can do. Groups and sites define where and on whose behalf they can do it.

How Do Technician Groups Work?

Groups organise technicians by team, such as Network, HR or Facilities. ManageEngine’s admin FAQ shows how to create separate groups and give each group its own email address, so requests land with the right team. The FAQ also describes configuring roles so technicians see only their group’s requests.

This setup keeps queues tidy and protects sensitive tickets. An HR group, for example, can handle confidential requests without exposing them to the entire IT team.

How Do Sites Help?

Sites represent locations or business units. Associating technicians with sites limits their view to the relevant part of the organisation. Large enterprises and managed service providers rely on this feature to separate customers and regions.

How Does Auto-Assignment Fit In?

The user guide mentions a Tech Auto Assign option that routes requests to technicians automatically. Combine it with groups, so the system assigns tickets fairly and technicians see only what they should.


How Do Licences Affect Technician Accounts?

Licensing affects how you manage access, so plan it early.

How Does ServiceDesk Plus Count Licences?

ManageEngine’s FAQ explains that you can add an unlimited number of technicians, but the licence depends on the number of technician logins. For example, a 10-technician licence allows ten technicians to log in and work at one time in that model. Check your current licence terms, since editions and licence models can differ.

How Do You Free a Licence?

If a technician no longer needs console access, remove the login rather than deleting the record. The FAQ describes editing the technician, choosing to remove the login and saving. This approach keeps the person’s history intact while it releases the licence.

How Can You Save Licences Without Losing Coverage?

Some staff only need to reply to tickets by email. ManageEngine’s FAQ notes that technicians can respond to notification emails, and the application appends those replies to the original request. That option lets occasional contributors help without holding a full login.


What Best Practices Keep Access Secure and Manageable?

Good habits matter more than any single setting. The following practices help most teams.

How Do You Apply Least Privilege?

Give each technician the minimum access they need. The National Institute of Standards and Technology (NIST) includes least privilege in its SP 800-53 control catalogue under the access control family. In ServiceDesk Plus, that means custom roles for specific jobs and very few SDAdmin accounts.

What Should You Review Regularly?

TaskSuggested frequency
Review technician rolesQuarterly
Check inactive technician loginsMonthly
Audit SDAdmin accountsQuarterly
Review technician groups and sitesQuarterly
Rotate or remove API keysEvery six months, or when staff change
Sync requester list with the directoryWeekly or automatically

How Do You Handle Joiners, Movers and Leavers?

Create a short checklist for each event. For joiners, create the account, assign the group and role, and confirm login. For movers, update the group, site and role. Also, for leavers, remove the login, reassign open tickets, revoke API keys and convert or archive the account. A consistent checklist prevents forgotten access.


What Common Problems Can You Fix Quickly?

Even a careful setup hits snags. The table below covers the most common ones.

ProblemLikely causeFix
A user cannot log inNo login enabled, or wrong domain selectionCheck the login details and the domain choice
A user is missing from the listImport did not run or filtered them outRerun the import or add the user manually
A technician cannot see requestsRole or group restricts the viewReview the role permissions and group settings
A technician sees too muchRole too broadCreate a narrower custom role
No licence availableAll technician logins in useRemove unused logins or expand the licence
Converted technician lacks rightsRole still set to the guest defaultAssign a suitable technician role

What Are the Key Takeaways?

Managing user accounts and technician access in ServiceDesk Plus follows a simple logic. Import requesters in bulk, convert or create technicians, assign roles that match each job, and use groups and sites to focus each technician’s view. Watch your licences by removing unused logins, and review access on a schedule.

ManageEngine ServiceDesk Plus – ITSM Software gives you the tools to do all of this from one console. However, the software cannot decide your policy for you. Define who needs what, keep SDAdmin rare, apply least privilege and document each role. Menu paths and licence terms vary between editions, so confirm details in ManageEngine’s official help pages before you make changes.

Start with a small pilot group, test the roles with real tickets and expand once the setup works smoothly.


What Questions Do Admins Ask Most About ServiceDesk Plus Accounts?

Can I Add an Unlimited Number of Technicians?

According to ManageEngine’s FAQ, the application allows unlimited technician records, but the licence limits how many technicians can log in. Confirm the exact terms for your edition and licence type.

How Do I Stop a Technician from Using a Licence Without Deleting Their Account?

Edit the technician’s record, remove the login and save the change. This keeps the history and frees the licence. You can restore the login later if the person returns to active support work.

Can Requesters Get Roles?

No. ManageEngine’s documentation states that roles apply only to technicians. To give a requester technician-level access, convert the requester to a technician first, then assign the appropriate role.


Recommended: