Skip to main content

Searching for Identities

EmpowerID's search engine provides powerful capabilities for locating information about user accounts, people, groups, and other organizational resources. The search functionality is designed to help administrators and users quickly find and manage identities across the organization.

Search Capabilities Overview

Each resource type in EmpowerID has a dedicated Find page with features including:

  • Locations tree for hierarchical navigation
  • Basic search fields for simple queries
  • Advanced search options for complex filtering
  • Results grid displaying matching resources
  • Contextual action links for resource management

EmpowerID provides two search modes to accommodate different scenarios:

Ideal for locating specific resources when you know a key identifier:

  • Enter a search term (name, logon name, email address)
  • EmpowerID returns exact matches based on searchable attributes
  • Quick and efficient for single-resource lookups

Figure 1: Using basic search on the Find User Accounts page Basic search example

Offers refined search capabilities for complex queries:

  • Combine multiple search criteria
  • Filter by location, domain, or system type
  • Search by account state (disabled, locked, never logged in)
  • Date range searches (last login, creation date)

Figure 2: Using the Locations tree to return all user accounts in the selected location Location tree search

Figure 3: Using advanced search to find accounts in a specific domain or directory Advanced search example

Searchable Attributes by Identity Type

EmpowerID's Identity Warehouse stores each identity object type with searchable attributes. For successful search results, search terms must match these allowable attributes.

User Account Search Terms

AttributeDescriptionSearch Result
NameThe name of the user accountReturns all user accounts with the specified name
FriendlyNameThe friendly or display name of the user accountReturns all user accounts with the specified friendly name
EmailThe email address of the user accountReturns all user accounts with the specified email address
FirstNameThe first name of the user accountReturns all user accounts with the specified first name
LastNameThe last name of the user accountReturns all user accounts with the specified last name
LogonNameThe logon name of the user accountReturns all user accounts with the specified logon name
UserPrincipalNameThe user principal name of the user accountReturns all user accounts with the specified user principal name

EmpowerID Person Search Terms

AttributeDescriptionSearch Result
NameThe name of the personReturns all people with the specified name
FriendlyNameThe friendly or display name of the personReturns all people with the specified friendly name
EmailThe email address of the personReturns all people with the specified email address
FirstNameThe first name of the personReturns all people with the specified first name
LastNameThe last name of the personReturns all people with the specified last name
LoginThe login of the personReturns all people with the specified login

Group Search Terms

AttributeDescriptionSearch Result
NameThe name of the groupReturns all groups with the specified name
FriendlyNameThe friendly or display name of the groupReturns all groups with the specified friendly name
EmailThe email address of the groupReturns all groups with the specified email address
EmpowerIDNameThe EmpowerID name of the groupReturns all groups with the specified EmpowerID name
EmpowerIDFriendlyNameThe EmpowerID friendly name of the groupReturns all groups with the specified EmpowerID friendly name
LogonNameThe logon name of the groupReturns all groups with the specified logon name
NetBiosNameThe NetBIOS name of the groupReturns all groups with the specified NetBIOS name
FQNThe FQN of the groupReturns all groups with the specified FQN
DistinguishedNameThe distinguished name of the groupReturns all groups with the specified distinguished name
DescriptionThe description of the groupReturns all groups with the specified description

Advanced Search Criteria

Advanced search allows combining multiple attributes for precise results. For example, to find all people with the last name "Stone" whose account is disabled, enter "Stone" as the last name and set the enabled flag to false.

Advanced search with multiple criteria

Combining Search Terms

Each attribute in the advanced search tables can be combined with others for more specific searches. This enables complex queries like finding all disabled accounts in a specific domain that haven't logged in within the last 90 days.

User Account Advanced Search Terms

AttributeDescriptionSearch Result
DisplayNameThe display name of the user accountReturns all user accounts with the specified display name
LogonNameThe logon name of the user accountReturns all user accounts with the specified logon name
Domain or DirectoryThe originating domain or directory of the user accountReturns all user accounts with the specified domain
FirstNameThe first name of the user accountReturns all user accounts with the specified first name
LastNameThe last name of the user accountReturns all user accounts with the specified last name
EmpowerID LoginThe login of the EmpowerID Person account linked to the user accountReturns all user accounts with the specified EmpowerID Login
DescriptionThe description of the user accountReturns all user accounts with the specified description
DisabledThe disabled state of the user account; can be true, false, or nullReturns all user accounts with the specified disabled state
Locked OutAllows you to search for users who are locked out; can be true, false, or nullReturns all user accounts with the specified locked out condition
Never Logged InAllows you to search for users who have never logged in; can be true, false, or nullReturns all user accounts with the specified logged in condition
Last Logged In BetweenAllows you to search for users whose last log in dates match those specifiedReturns all user accounts with the specified last log in dates

Person Advanced Search Terms

AttributeDescriptionSearch Result
FirstNameThe first name of the personReturns all people with the specified first name
LastNameThe last name of the personReturns all people with the specified last name
TitleThe title of the personReturns all people with the specified title
DepartmentThe department of the personReturns all people with the specified department
Street AddressThe street address of the personReturns all people with the specified street address
EmpowerID LoginThe login of the personReturns all people with the specified EmpowerID Login
EmailThe email address of the personReturns all people with the specified email address
EnabledThe enabled state of the user account; can be enabled, disabled, or nullReturns all user accounts with the specified state
ManagerAllows you to search for people by managerReturns all people with the specified manager
Last Logged In BetweenAllows you to search for people whose last log in dates match those specifiedReturns all people with the specified last log in dates
Valid Until BetweenAllows you to search for people whose valid until between dates match those specifiedReturns all people with the specified valid until between dates

Group Advanced Search Terms

AttributeDescriptionSearch Result
DisplayNameThe friendly or display name of the groupReturns all groups with the specified display name
LogonNameThe logon name of the groupReturns all groups with the specified logon name
Group TypeThe type of group, e.g., security universal, distribution, etc.Returns all groups with the specified group type
By MemberMember of groupReturns all groups where the specified user is a member
By OwnerOwner of groupReturns all groups where the specified user is the owner
NotesNotes set for the groupReturns all groups containing the specified text
DescriptionThe description of the groupReturns all groups with the specified description
No MembersAllows you to search for groups without members; can be true, false, or nullReturns all groups with the specified membership state
Publish In IT ShopAllows you to search for groups published in the IT Shop; can be true, false, or nullReturns all groups with the specified publish state
Is High Security GroupAllows you to search for groups flagged as high security; can be true, false, or nullReturns all groups with the specified security state
System TypeAllows you to search for groups belonging to a specific system type, such as AzureReturns all groups belonging to the specified system type

Search Best Practices

  • Use specific identifiers when possible (email addresses, logon names)
  • Enter complete or partial attribute values
  • Search is case-insensitive for better flexibility
  • Start with broader criteria and refine as needed
  • Combine location filtering with attribute searches for faster results
  • Use date ranges to identify stale or inactive accounts
  • Save complex searches for recurring audit or compliance tasks

Example Search Scenarios

Use advanced search capabilities to address common administrative needs:

Account Lifecycle Management:

  • Use "Last Logged In Between" to identify accounts with no recent activity
  • Combine "Disabled" state with date filters to review account status

Identity Governance:

  • Search for People by "Manager" to review organizational reporting structures
  • Use "Group Type" and "System Type" to audit groups by classification

Security and Compliance:

  • Filter groups using "Is High Security Group" for access reviews
  • Search by "By Owner" to identify resources under your management