Tier: User Inventory is included in the Protect tier. Customers on Connect or Discover see device inventory only — talk to your account team about upgrading if you need user-side visibility.
Overview
The User Inventory at/user-inventory is the people-side mirror of Devices. Where Devices answers “what hardware do we have?”, User Inventory answers “who is using it, and what apps do they touch?”.
Users are pulled from your identity sources (Microsoft Entra ID, Okta, Google Workspace, on-prem AD), enriched with HR-style attributes (department, job title, manager), and correlated against the devices and cloud apps each person uses.
Columns
The grid is organised into four column groups:
Email is the matching key used to correlate users across every integration. Tags come from the Logic Engine.
Click any column header’s sort icon to sort. The same query language used in Devices works here, scoped to user fields.
Drilling into a user
Click a row to open the user detail panel. It shows:- Profile: avatar, name, email, department, job title, accounts (Microsoft 365, OnPrem AD, Duo, etc.)
- Recent Devices: every device this user has signed into, with last-seen times — useful for joiner-mover-leaver flows
- Activity timeline: when this user last appeared in each integration
- Tags: user-level tags from the Logic Engine
Filtering the user list
User Inventory uses the same query grammar (field:value, AND / OR / NOT) as Devices, but with user-specific fields. The exact field set is best discovered via the search bar’s autocomplete — click the search input and type a few characters to see available fields with descriptions.
Common patterns:
- Filter by tag:
tags:Phishing-Campaign-Q2 - Filter by department or job title via the user-detail fields exposed in autocomplete
- Negate to find exceptions:
NOT tags:Stock
Use cases
Offboarding audit
Quarterly: find users with stale last-seen times and at least one associated device. Validate against HR records.
VIP coverage check
Tag executives via Logic Engine, then verify every VIP device meets your strictest security baseline.
License reclaim
Cross-reference users who haven’t logged in recently with software licenses to identify reclaim candidates.
Phishing follow-up
Tag users who clicked a phishing link, then build a follow-up Action checking device-level vitals.
How user matching works
Protect matches a user across tools using email (themail property) as the primary key — not UPN, which can differ.
The same matching strategy is used for SSO user enablement. If your IdP doesn’t populate the mail attribute, see Troubleshooting.
Cross-references
Device Management
Pivot users → devices
Tags & Logic Engine
Apply user tags via rules
Access Control
Manage Protect users themselves (separate from end-user inventory)
Two kinds of “users”: This page documents the end-user inventory — every person in your organisation pulled from identity providers. To manage Protect platform users (people who log into the Protect console itself), see Access Control and Settings → Users.