---
title: Editing User Properties
slug: kronpam-reference-guide-3-5-0/editing-user-properties
description: Learn how to adjust the properties of Kron PAM users with this comprehensive document. Discover how to manage external directory sources, enforce password changes, lock/unlock users, configure temporary user settings, specify lock reasons, assign phone nu
docTags: 
createdAt: 2022-07-25T07:27:05.000Z
---

Authorized users can adjust the properties of Kron PAM users.&#x20;

To set user properties:

1.   Navigate to **Users > Users.**
2.   Search user from the search bar.
3.   Click on the user's action menu and Select **Show Properties.**
4.   Add/Edit the user’s properties and click **Save**.

***Property Keys***:

**externalDirectorySource**: This value is set automatically a&#x73;**&#x20;an external source name** by the defined LDAP integration. The value is set according to th&#x65;**&#x20;sc.integration.ldap.source.name\_n** value defined in the system config parameter.

**forcePasswordChangeOnNextLogin**: If this parameter’s value is set as **true**, users are forced to change their password on the next login.

**isLocked**: Can be set as **true** or **false** to lock or unlock users, respectively.

**isTemporaryUser**: If a user is configured as a temporary user from the GUI (see section [Temporary User](docId:26SLMLZ-EYM1fuThiPiT5)) the value of the parameter is set as **true**. While using this functionality, the **temporaryUserStartTime** and **temporaryUserEndTime&#x20;**&#x70;arameters are set in milliseconds.&#x20;

**temporaryUserEndTime**: This parameter specifies the **end-time** for a temporary user in milliseconds. It is set automatically when a user is created as a temporary user in Kron PAM.

**temporaryUserStartTime**: This parameter specifies the **start-time** for a temporary user in milliseconds. It is set automatically when a user is created as a temporary user in Kron PAM.

**lockReason**: If the user is locked, this value is set with a reason for the lock, such as **User cannot be found on Active Directory/LDAP**, **User is passive on Active Directory/LDAP**, or **Locked by username**.

**phoneNumber**: If a user’s phone number is entered, this property is set as a user property.

**ubaThreshold**: The threshold value is used for policy enforcement when executing UBA commands. When users exceed the threshold value by executing commands that are defined as UBA commands, the commands are blocked and can no longer be executed.&#x20;

**unlockOnPasswordChanged**: This parameter is automatically set for a user when the user is locked for the reasons **Suspended temporarily due to successive invalid login attempts** or **Too many failed login attempts**. After the user changes their password, using the **forgot password&#x20;**&#x66;eature, the user is automatically unlocked.

**unlockTime**: This parameter is automatically set on a user in milliseconds, like 1576851980209, when the user is locked by reason **Suspended temporarily due to successive invalid login attempts**. When the time has expired, the user is automatically unlocked. This field is for information purposes only. Unlock time can be configured with the **user.suspend.forMillis** parameter from the System Config Man screen.
