Summary and recommendation
Infor HCM user management can be run manually, but complexity usually increases with role models, licensing gates, and offboarding dependencies. This guide gives the exact mechanics and where automation has the biggest impact.
Infor HCM runs on Infor OS (Ming.le) and uses Infor Federation Services (IFS) as the identity and access layer. User management lives in the IFS Admin Console, reachable at your tenant URL under Infor OS > User Management.
Every app in the Infor CloudSuite ecosystem - Talent Management, Workforce Management, Payroll - inherits access from the security roles and data groups assigned in IFS.
The permission model is role-based (RBAC), with an additional data-security layer controlled by Security Groups and Organizational Unit (OU) filters. Role assignment controls what a user can do; Security Group and OU assignment controls which employee records they can see. Both layers must be configured for a user to function correctly.
Quick facts
| Admin console path | Infor OS (Ming.le) > User Management (via Infor Federation Services / IFS Admin Console) |
| Admin console URL | Official docs |
| SCIM available | Yes |
| SCIM tier required | Enterprise |
| SSO prerequisite | Yes |
User types and roles
| Role | Permissions | Cannot do | Plan required | Seat cost | Watch out for |
|---|---|---|---|---|---|
| System Administrator | Full access to Infor OS administration, user provisioning, security role assignment, tenant configuration, and integration management via IFS. | Enterprise (CloudSuite) | Custom contract pricing; not publicly disclosed. | System Administrator access is typically restricted to a small number of named users defined at contract time. Expanding admin seats may require contract amendment. | |
| Security Administrator | Manages security roles, permission sets, and user-role assignments within Infor HCM modules. Can create and assign custom roles. | Cannot modify tenant-level infrastructure settings or IFS federation configuration; those require System Administrator. | Enterprise (CloudSuite) | Custom contract pricing; not publicly disclosed. | Role boundaries between Security Administrator and System Administrator vary by implementation and may require Infor Professional Services to configure correctly. |
| Named User (Employee/Manager/HR Professional) | Access scoped to assigned HCM modules (e.g., Talent Management, Workforce Management, Payroll) and data security groups. Permissions determined by assigned security roles. | Cannot access admin consoles or modify security configurations. | Enterprise (CloudSuite); specific module access depends on licensed modules. | Custom contract pricing; per-user costs not publicly disclosed. | Users must be provisioned in both Infor OS (IFS) and the specific HCM application. Provisioning in one layer without the other results in login failures. |
Permission model
- Model type: role-based
- Description: Infor HCM uses a role-based access control (RBAC) model administered through Infor OS Security. Security roles are assigned to users and control access to application features, data classes, and actions. Data security is further controlled through Security Groups and Organization Unit (OU) filtering, which restrict which employee records a user can view or modify.
- Custom roles: Yes
- Custom roles plan: Enterprise (CloudSuite); custom role creation is available to Security Administrators within the platform.
- Granularity: Role-level access to application features combined with data-level filtering via Security Groups and OU assignments. Field-level security is available in some HCM modules.
How to add users
- Log in to the Infor OS Admin Console (IFS) as a System Administrator or Security Administrator.
- Navigate to User Management within IFS.
- Select 'Create User' and enter required identity fields.
- Assign the user to the appropriate Infor OS tenant and application.
- Assign one or more Security Roles appropriate to the user's function.
- Assign the user to relevant Security Groups and Organizational Units for data-level access.
- If SSO is configured, ensure the user's identity provider account is linked or will be federated via SAML/SCIM.
- Save and notify the user of their access credentials or SSO login path.
Required fields: First Name, Last Name, Email Address, Username (typically email or employee ID), Tenant assignment, Security Role(s)
Watch out for:
- Users must be provisioned in both Infor OS (IFS) and the specific HCM application layer; a gap between the two causes authentication errors.
- If SCIM provisioning is active, manual user creation in IFS may conflict with IdP-driven provisioning and cause duplicate or inconsistent records.
- Security Group and OU assignments are separate from role assignment and are frequently missed during onboarding, resulting in users with correct roles but no visible data.
- Infor HCM does not publicly document a self-service user invitation flow; provisioning is administrator-driven.
| Bulk option | Availability | Notes |
|---|---|---|
| CSV import | Yes | Infor OS Admin Console > User Management > Import Users (CSV template available within the console; format varies by tenant version). |
| Domain whitelisting | No | Automatic domain-based user add |
| IdP provisioning | Yes | Enterprise; SCIM 2.0 provisioning supported with Okta and Microsoft Entra ID. SSO is a prerequisite for SCIM provisioning. |
How to remove or deactivate users
- Can delete users: No
- Delete/deactivate behavior: Infor HCM follows standard HCM/ERP data retention practices where employee and user records are typically deactivated (inactivated) rather than permanently deleted, to preserve audit trails, historical payroll records, and compliance data. Hard deletion of user records is generally not supported through the standard admin UI and may require Infor Professional Services or a database-level operation under specific contractual terms.
- Log in to the Infor OS Admin Console (IFS) as a System Administrator or Security Administrator.
- Navigate to User Management and locate the user record.
- Set the user's status to 'Inactive' or 'Disabled'.
- Remove or revoke assigned Security Roles to prevent any residual access.
- If the user is provisioned via SCIM/IdP, deprovision the user in the identity provider to trigger automatic deactivation in Infor OS.
- In the HCM application layer, terminate or inactivate the associated employee record per HR workflow (if applicable).
| Data impact | Behavior |
|---|---|
| Owned records | Employee records, transaction history, and HCM data created by or associated with the user are retained per the organization's data retention policy. Records are not deleted upon deactivation. |
| Shared content | Shared reports, dashboards, or workflow configurations owned by the deactivated user may become inaccessible or orphaned; reassignment should be performed before deactivation. |
| Integrations | Active API tokens or integration credentials associated with the user account should be reviewed and revoked separately; deactivation alone may not invalidate service account tokens. |
| License freed | Deactivating a user should free the associated named-user license seat for reassignment, but license reclamation timing depends on contract terms and may require confirmation with Infor account management. |
Watch out for:
- Deactivating a user in Infor OS does not automatically terminate their employee record in the HCM application; both actions must be performed independently.
- If SSO/SCIM is in use, deprovisioning must occur in the IdP to fully block access; disabling only in Infor OS may leave the IdP session active.
- License seat reclamation is not always immediate and may require manual confirmation with Infor support or account management.
- Orphaned workflow tasks or approval chains assigned to a deactivated user can stall business processes; reassignment of pending tasks is recommended before deactivation.
License and seat management
| Seat type | Includes | Cost |
|---|---|---|
| Named User License | Access to contracted Infor HCM modules for a single identified user. Specific module access (e.g., Talent, Workforce Management, Payroll) depends on licensed modules in the contract. | Custom contract pricing; not publicly disclosed. |
| Concurrent User License | Shared pool of simultaneous sessions across a defined user population. Availability depends on contract type; not all HCM deployments offer concurrent licensing. | Custom contract pricing; not publicly disclosed. |
- Where to check usage: Infor OS Admin Console > License Management (availability and path vary by tenant version and contracted modules; some organizations rely on Infor account management reports for usage data).
- How to identify unused seats: Infor OS may provide last-login timestamps within User Management. Identifying unused seats typically requires cross-referencing active user accounts against last-login data or requesting a usage report from Infor support.
- Billing notes: Pricing is contract-based and negotiated directly with Infor or via AWS Marketplace for CloudSuite deployments. Implementation costs are separate from license fees and typically range from $500K to $5M+ depending on scope. Per-user pricing is not publicly disclosed. License true-ups and seat adjustments are handled through contract amendments with the Infor account team.
The cost of manual management
Manual provisioning in Infor HCM carries a compounding overhead that most teams underestimate. Every app requires two separate provisioning actions: one in Infor OS/IFS to create the login identity, and one in the HCM application layer to create or activate the employee record.
Missing either step produces login failures or blank-screen experiences with no clear error.
Security Group and OU assignments are a third, frequently skipped step. Users provisioned with correct roles but no Security Group assignments will authenticate successfully but see no data - a gap that typically surfaces only after the user reports the issue.
Identifying unused license seats adds further overhead, as built-in visibility is limited and usage data often requires a manual report request from Infor support.
What IT admins are saying
Administrators consistently flag the dual-layer provisioning requirement - IFS plus the HCM application - as the leading source of onboarding errors. The failure mode is subtle: the user can log in, but modules or data are missing because one layer was not completed.
Security Group and OU configuration is widely described as complex and under-documented, with many teams requiring Infor Professional Services to get it right.
SCIM setup with Okta and Entra ID is reported as sensitive to attribute mapping errors, and detailed admin documentation is largely behind authenticated tenant portals, limiting self-service troubleshooting.
Offboarding carries its own compliance risk: deactivating a user in Infor OS does not terminate their HCM employee record. Teams that complete only one step may leave payroll or benefits active after access is revoked.
Common complaints:
- Users report that the dual-layer provisioning requirement (Infor OS/IFS plus the HCM application layer) is a frequent source of onboarding errors, with users able to log in but seeing no data or modules.
- Security Group and Organizational Unit configuration is described as complex and poorly documented, often requiring Infor Professional Services engagement to configure correctly.
- Administrators report difficulty identifying unused license seats without requesting manual reports from Infor support, as built-in license usage visibility is limited.
- The separation between deactivating a user in Infor OS and terminating an employee record in the HCM application is a common source of compliance risk, as organizations may complete one step but not the other.
- SCIM provisioning setup with Okta and Entra ID is reported to require significant configuration effort and is sensitive to attribute mapping errors that cause provisioning failures.
- Community members note that detailed admin documentation for Infor HCM is largely behind authenticated tenant portals, making it difficult for new administrators to self-serve.
The decision
Manual administration is viable for organizations with a stable, low-turnover workforce and a dedicated Infor administrator who understands both the IFS and HCM application layers. The RBAC model is expressive, and Security Groups provide fine-grained data access control when configured correctly.
For organizations with frequent onboarding and offboarding, the dual-layer provisioning requirement and the separation between IFS deactivation and HCM termination create meaningful compliance exposure. SCIM provisioning via an IdP reduces IFS provisioning overhead but does not eliminate the need to manage HCM employee records separately.
Teams should confirm Security Group and OU assignment ownership before going live with any provisioning workflow.
Bottom line
Infor HCM's access model is powerful but layered: every app in the suite depends on IFS identity, RBAC roles, and data-level Security Group assignments all being correct simultaneously.
Manual administration works at small scale with experienced operators, but the dual-layer provisioning requirement - IFS plus HCM application - and the independent offboarding steps for login and employment records create compounding risk as headcount or turnover grows.
Organizations should treat Security Group and OU configuration as a first-class provisioning step, not an afterthought, and establish a clear offboarding checklist that covers both IFS deactivation and HCM termination workflow completion.
Automate Infor HCM workflows without one-off scripts
Stitchflow builds and maintains end-to-end IT automation across your SaaS stack, including apps without APIs. Built for exactly how your company works, with human approvals where they matter.