FAQ
Common questions and quick answers
Since DEXIOS uses Microsoft Azure AD for authentication, you cannot reset your password directly in DEXIOS.
Reset password:
Option 1: Self-Service Password Reset (SSPR)
1. On the Microsoft login page, click “Forgot your password?
2. Follow the identity verification instructions
3. Set your new password
4. Sign in with the new password
Option 2: Contact the IT help desk
- When SSPR is unavailable
- Contact your IT department
- Your IT department can reset your password
After resetting:
- Sign in with the new password
- Change the temporary password if necessary
Common causes and solutions:
1. Wrong password
- ✅ Check upper/lower case
- ✅ Turn off Capslock
- ✅ Try resetting password
2. Wrong username
- ✅ Use your full business email
- ✅ Example: max.mustermann@firma.de, not just “max.mustermann”
3. Account suspended
- ❌ After several failed attempts, the account is temporarily suspended
- ⏱️ Wait 15-30 minutes
- ☎️ Or contact IT help desk
4. Account not activated
- Your user account has not yet been activated
- Contact your dexios administrator
5. No role assigned
- You can sign in but see “No Permission”
- Contact your dexios administrator for a role assignment
6. Browser issues
- ✅ Clear browser cache and cookies
- ✅ Access DEXIOS from another browser
- ✅ Disable browser extensions temporarily
- ✅ Allow pop-ups for DEXIOS
7. Multi-factor authentication (MFA) blocked
- MFA code incorrect or expired
- Request again
- In case of device loss: contact the IT help desk
8. Network issues
- ✅ Check your Internet connection
- ✅ Try from another network
- ✅ Check if VPN is required
Since DEXIOS uses Microsoft Azure AD, change your password via Microsoft, not directly in DEXIOS.
Change password:
Method 1: Through Microsoft account
1. Go to https://account.microsoft.com
2. Sign in with your business account
3. Select Security → Password
4. Enter your current password
5. Enter your new password twice
6. Save the change
Method 2: When you log on (Windows)
- Press Ctrl+Alt+Delete
- Select “Change password”
- Follow the instructions
Method 3: About Office 365
- Go to https://portal.office.com
- Click on your profile picture → “My account”
- Select “Security & Privacy” → “Password”
Notice
Important: After the change: The new password is valid for all Microsoft services
If you don't see certain menu items or functions, this is due to your permissions.
Possible reasons:
1. Missing role
- You have not been assigned a corresponding role
- Example: “Devices” menu item only visible with “Device” permission
- Solution: Contact your administrator for role assignment
2. Wrong permission level
- You only have read permission (OPERATION), not write permission (EDIT)
- Example: You see devices but the “New device” option is missing
- Solution: Administrator must increase your permission
3. Administrative unit restriction
- You only see data from your own administrative unit
- Data from other organizational units is invisible to you
- This is normal and is used for data isolation
4. Missing license
- Some features require a special license
- Example: Smart Managed Services only with the appropriate license
- Solution: Administrator must extend license
5. Not yet configured
- Function has not yet been set up in the system
- Example: Workflows can only be used after approval rules have been configured
- Solution: Administrator must activate/configure the function
How to verify your role:
1. Ask your administrator
2. Or: Administrator can view your role assignments in “Settings” → “User Management”
After several failed login attempts, a protection mechanism is in place:
Expiration:
After 5-10 failed attempts (depending on your organization):
- Your account is temporarily suspended
- You receive an error message: “Account temporarily suspended”
- The lock down usually lasts 15-30 minutes
Why is this being done?
- Protection against brute force attacks
- Prevents automated attacks
- Microsoft Azure AD security mechanism
What can you do?
Option 1: Wait
- Wait 15-30 minutes
- Then try again with the correct password
Option 2: Self-Service Unlock (if available)
- Use Microsoft self-service features to unlock
- Follow the identity verification instructions
Option 3: IT help desk
- Contact your IT department It can manually unlock your account
- IT can manually unlock your account
- Use this option for urgent cases
**Tip: ** After the third failed attempt, note that you might be using an incorrect password and reset it before your account is suspended.
Here's how to find out your role:
Method 1: Ask your administrator
- Your dexios administrator can tell you your role assignments
Method 2: Derive from visible functions
- Which menu items do you see in the sidebar?
- Can you only view or also edit data?
Typical role profiles:
Minimum permission (end user):
- You are watching: Dashboard, My Permissions, My Requests
- You can: View your own data, submit applications
Report users:
- Additionally: Reports
- You can: create and export reports
Approver:
- In addition: permit applications
- You can: process others' requests
People administrator:
- You are watching: Access management (people, groups)
- You can: create, edit, delete people
Access control administrator:
- You are watching: Access Management (Access Manager, Devices)
- You can: manage permissions, configure devices
System administrator:
- You are watching: All areas including settings
- You can: Configure everything
Tip
Please contact your administrator for a detailed list.
DEXIOS works with a role-based authorization system. You only see areas that you are eligible for.
Common reasons for lack of access:
1. Missing functional area authorization
- Each area (people, devices, reports, etc.) requires a specific permission
2. Read permission only
- You can see data but not edit it
- Options such as “New”, “Edit”, “Delete” are missing
3. Administrative unit restriction
- You only have access to data from your own organizational unit
- Data from other areas is not visible to you
4th hierarchical level
- You have access to your own and subordinate administrative units
- Higher levels are not visible
5. Licensing
- Some features require a license and are not available without an appropriate license
Eligible persons:
System administrators:
- Have full permission to manage and assign roles
- Can create, edit, delete roles
IT administrators:
- Can manage users and assign roles
User administrators:
- Have access to user management
- Can create new users
- Can assign roles to existing users
Regular users:
- Can do their own role not change
- Need to contact administrator for changes
Role change takes place in:
- Settings → System Settings → User Management (only visible to administrators)
DEXIOS uses various status icons and colors:
Person status:
Device status:
[de]
Badge status:
Request status:
symbol | Status | meaning |
🔵 Blue | Open | Awaiting approval |
🟢 Green | Approved | Approved and implemented |
🔴 Red | Rejected | Not approved |
⚪ Gray | Cancelled | Withdrawn |
The filter option can be used on any subpage.
The search function is carried out via the magnifying glass icon and
The features depend on your role. Here is an overview:
Available to all users:
- View your profile data
- Change language
- Receive and customize notifications
- View events and notifications
End users:
- Check your own access rights
- Request temporary access
- Track the status of your applications
Approver:
- View and forward applications
- Approve or reject requests
Personnel administrator:
- Create, edit, delete people
- Maintain personal master data
- Assign and manage badges
- Create and manage groups of people
- Assigning qualifications
Facility Manager/ Safety Officer:
- Grant and withdraw access rights
- Assign permissions to time models
- Manage and configure devices
- Monitor device status
- Manage blacklists
Report creator:
- Generate reports
- Save report configurations
- export data (CSV, PDF)
- Attendance evaluations
- Access statistics
System administrators:
- Create and manage users
- Define and assign roles
- Configure administrative units
- Upload and manage licenses
- Set up email integration
- Configuring SAP Interfaces
- Change system settings
Data is saved automatically or via the button Save.
Make sure that
- all mandatory fields (marked with *) have been completed
- inputs meet the requirements
- you have sufficient privileges
- you have met possible requirements (e.g. Access authorization only possible if person and device exist
- there is a connection to the server
Mandatory fields are marked with a red star (\ *) marked.
Common mandatory fields by area:
People:
- ✅ First name\ *
- ✅ Last name\ *
- ✅ Personnel number\ * (must be unique)
- ✅ Administrative Unit\ *
- ⚠️ From date for limited access
devices:
- ✅ device ID\ * (must be unique)
- ✅ device name\ *
- ✅ device type\ * (MAIN, READER, or OFFLINE)
- ✅ Administrative Unit\ *
- ⚠️ IP address (for online devices)
- ⚠️ OSS site (for offline devices)
Access rights:
- ✅ person or group of people\ *
- ✅ device or device group\ *
- ⚠️ From date (if time limited)
Time bookings (reports):
- ✅ From date\ *
- ✅ To date\ *
- ⚠️ Maximum 365 days gap
user:
- ✅ username\ * (must be unique)
- ✅ At least one roll\ *
- ✅ Administrative Unit\ *
Workflows:
- ✅ Workflow name\ *
- ✅ At least one approver\ *
- ✅ Administrative Unit\ *
Time models:
- ✅ Name\ *
- ✅ At least one time window for a weekday\ *
Note: Mandatory fields may vary depending on your organization's configuration.
You can activate or deactivate notifications under Settings.
Configure notifications:
Select notification settings
Click on your profile picture (bottom left)
Select “Notification Settings” from the menu
Configure per severity level
Level 1 — Information: - ☑️ Platform notifications (in-app) - ☐ Email notifications - ☐ SMS notifications (not yet active)
Level 2 — Alerts: - ☑️ Platform Notifications - ☑️ Email Notifications - ☐ SMS Notifications
Level 3 — Critical: - ☑️ Platform notifications - ☑️ Email notifications - ☑️ SMS notifications (when available)
Assign time model (optional)
Select a time model (example: “Mon-Fr 08:00-17:00 only”)
Notifications are only sent during this time
Enable emergency override (recommended)
☑️ Enabled: Level 3 events are always pushed through
Even outside the time model
Save: Settings are activated immediately
Tip
Deactivate level 1 emails so as not to clutter up your inbox. Keep Level-2 and Level-3 activated for important events
DEXIOS uses extensive security measures:
Authentication:
- ✅ Microsoft Azure AD integration
- ✅ Single sign-on (SSO)
- ✅ Multi-factor authentication (MFA) optional
- ✅ Token-based authentication (JWT)
Encryption:
- ✅ HTTPS/TLS for all data transfers
- ✅ Encrypted storage of sensitive data
- ✅ Secure password hashing (in Azure AD)
Access control:
- ✅ Role-based authorization system (RBAC)
- ✅ Management unit-based data isolation
- ✅ Granular permissions (read, write, configure)
- ✅ Automatic authentication every time you access
Data separation:
- ✅ Multi-tenancy: Strict separation between clients
- ✅ Admin units: separation within organizations
- ✅ No cross-tenant access possible
Auditing:
- ✅ All changes are logged
- ✅ Who changed what and when
- ✅ Traceability for compliance
Session security:
- ✅ Automatic logout when inactive
- ✅ Session token invalidation upon logout
- ✅ Session hijacking protection
Network security:
- ✅ Firewalls and Intrusion Detection
- ✅ DDoS protection (when deployed in the cloud)
- ✅ Regular security updates
Compliance:
- ✅ GDPR-compliant
- ✅ ISO 27001 processes (depending on deployment)
- ✅ Regular security audits
Since DEXIOS uses Microsoft Azure AD, your organization's password policies apply.
Recommended password properties:
Length:
- ✅ At least 12 characters
- ✅ The longer the better (16+ characters very safe)
Complexity:
- ✅ Capital letters (A-Z)
- ✅ lowercase letters (a-z)
- ✅ Numbers (0-9)
- ✅ Special characters (! @#$%^&* () _+-= [] {} |;:,. <>?)
Good passwords:
- ✅ Passphrases: “My 1st dog doesn't like any&cats!
- ✅ Random strings: “KP9$mn2 #vL7 @qR3"
- ✅ Use a password manager to generate
Bad passwords (avoid):
- ❌ Simple words: “password”, “admin”, “summer 2026"
- ❌ Personal information: name, date of birth, phone number
- ❌ Keyboard pattern: “qwertz123”, “1234567890”
- ❌ Reuse old passwords
- ❌ password = username
Best practices:
- ✅ Unique password for every system
- ✅ Use a password manager
- ✅ Change password regularly (recommended every 90 days)
- ✅ Never share passwords
- ✅ Don't write down (except in an encrypted password manager)
Multi-factor authentication:
- Even more secure than strong passwords alone
- Use MFA when available
- No access possible even if the password is stolen
Automatic logout occurs:
After inactivity:
- No interaction with DEXIOS for a specified period of time (typical: 15-30 minutes [configured by administrator])
After session timeout:
- Maximum session duration exceeded (typical: 8-12 hours)
What's happening:
- Session is ended
- Unsaved changes are lost
- When used again: new login required
Tip to avoid data loss:
- Save regularly as you work
- Before long breaks: log out manually and log in again later
Manual logout (recommended):
- At the end of your work → Profile → “Unsubscribe”
- Especially on shared computers
Google Chrome (recommended):
- ✅ version 90 or newer
- ✅ Best performance
- 💻 Windows, MacOS, Linux
Microsoft Edge (Chromium):
- ✅ version 90 or newer
- 💻 Windows, MacOS
Mozilla Firefox:
- ✅ version 88 or newer
- 💻 Windows, MacOS, Linux
Safari:
- ✅ version 14 or newer
- 💻 macOS, iOS
Does DEXIOS work offline?
No, DEXIOS requires an Internet connection:
Workarounds:
For short offline phases:
- Save regularly
- Write down important information externally
Mobile data connection:
- Alternative if WLAN fails → Use smartphone as hotspot/Tethering with laptop
Common validation issues:
1. Uniqueness not given
- ❌ Problem: “Personnel number already assigned”
- ✅ Solution: Use a different, unique personnel number
2. Date logic incorrect
- ❌ Problem: “From date must be before to date”
- ✅ Solution: Check date order, correct
3. Invalid format
- ❌ Problem: “Invalid email address”
- ✅ Solution: Format: name@firma.de (@ and dot required)
4. Required field empty
- ❌ Problem: “This field is required”
- ✅ Solution: Fill out all fields with a red star (*)
5. Character length exceeded
- ❌ Problem: “Maximum 255 characters allowed”
- ✅ Solution: abbreviate the text
6. Invalid characters
- ❌ Problem: “Only letters, numbers and -_ allowed”
- ✅ Solution: Remove special characters
7. Value range exceeded
- ❌ Problem: “The maximum period of time is 365 days”
- ✅ Solution: Select a shorter period
8. Dependencies not met
- ❌ Problem: “Badge is already assigned to someone else”
- ✅ Solution: First remove a badge from an old person, then reassign
9. circular reference
- ❌ Problem: “Administrative unit cannot be superior to itself”
- ✅ Solution: Check hierarchy logic
What do the technical error messages mean?
Common error messages and meaning:
“401 Unauthorized”/“Unauthorized”
- Meaning: You are not logged in or session has expired
- Solution: Sign in again
“403 Forbidden”/“Access denied”
- Meaning: You do not have permission for this action
- Solution: Contact administrator for permissions
“404 Not Found”
- Meaning: The page you requested does not exist
- Solution: Check URL, go back to homepage
“500 internal server error”
- Meaning: error on the server
- Solution: Try again later, contact administrator
“503 Service Unavailable”
- Meaning: server is temporarily unavailable (maintenance, overload)
- Solution: Wait a few minutes and try again
“Network Error”/“Network Error”
- Meaning: connection to the server interrupted
- Solution: Check Internet connection, reload page
“Timeout”
- Meaning: Request took too long
- Solution: Try again using filters for large amounts of data
“Bad Request”/“Invalid Request”
- Meaning: Your input was not valid
- Solution: Validate form inputs, correct errors
“Conflict”/“Conflict”
- Meaning: Simultaneous editing by other users
- Solution: Reload data, make changes again
“Validation Error”/“Validation Error”
- Meaning: Entries do not meet the requirements
- Solution: Read error message, correct affected fields
In case of incomprehensible errors:
- Record error message (screenshot)
- Write down what you've done
- Contact IT Helpdesk with this information
Yes, DEXIOS offers export functions:
Export formats:
CSV (comma-separated values):
- ✅ Standard spreadsheet format
- ✅ Open with Excel, LibreOffice, Google Sheets
- ✅ Further processing possible
- ✅ Suitable for large amounts of data
PDF:
- ✅ Formatted document
- ✅ For archiving and presentation
- ✅ Not editable
- ✅ Professional layout
What can be exported:
✅ Reports:
- Time bookings
- Access bookings
- With all filters applied
✅ Lists:
- lists of persons
- device lists
- Time models
- Current view with filters
How to export:
Reports:
1. Generate report with filters
2. Run report
3. Click on CSV or PDF icon
4. Downloading file
5. Open in the appropriate application
lists:
1. Open the desired list (e.g. people)
2. Set filters (optional)
3. Click on export button
4. Select format
5. Download starts
Data protection information:
- ⚠️ Exports may contain personal data
- ✅ Keep confidential
- ✅ Store in encrypted form
- ✅ Delete after use
- ✅ No transfer to unauthorized persons
For the Exporting:
CSV (.csv):
- ✅ Standard text format with separator
- ✅ Compatible with Excel, OpenOffice, Google Sheets
- ✅ Character encoding: UTF-8
- ✅ Separator: comma or semicolon (depending on the system)
PDF (.pdf):
- ✅ Portable document format
- ✅ Universally readable
- ✅ Get formatting
- ✅ Suitable for archiving
Unsupported formats:
- ❌ Excel (.xlsx) — Use CSV and open in Excel
- ❌ XML — Not currently available
- ❌ JSON — Only for API
Photos (for people):
- ✅ JPEG (.jpg, .jpeg)
- ✅ PNG (.png)
- ⚠️ Maximum file size: typically 5-10 MB
- ⚠️ Recommended resolution: 300x400 pixels for ID cards
personal data:
What you can change yourself:
- ⚠️ Mostly read-only — personal data comes from central personnel management
- ✅ You can always view your data
Here's how you see your data:
1. Click on your profile picture (bottom left)
2. Select the “Personal Settings” tab
3. See: name, personnel number, company, department, photo, contact details
What you can change:
✅ Notification settings:
- In Profile → “Notification Settings”
- Enable/disable email notifications
- SMS notifications (when available)
- Time model for contacting
✅ Language setting:
- In Profile → “Language and System”
- choose German or English
What you can'T change directly:
❌ Personal master data:
- Name, personnel number, department, company
- photo
- contact details (e-mail, telephone)
How to change master data:
- Contact your HR department
- Or: dexios administrator (can edit personal data)
1. Open profile
- Click on your profile picture (at the bottom left of the footer)
2. Select tab
- Select “Language and System” tab
3. Select language
- Drop down menu: choose your preferred language
- 🇩🇪 German
- 🇬🇧 English
4. Automatic application
- Change is accepted immediately
- All texts are translated into the selected language
What is translated:
✅ Fully translated:
- Menu items and navigation
- Field names in forms
- buttons (save, cancel, etc.)
- System messages and error texts
- Notifications
- Date formats and calendars
❌ Not translated:
- Custom content (names, descriptions entered by you)
- Technical IDs (device IDs, personnel numbers) *Your language choice is saved:
- Individually per user
- Automatically active when you log in again
- Applies to all devices you sign in to
Stage 1: Local DEXIOS Administrator
Responsible for:
- User accounts and roles
- Permissions
- Configuration questions
- Data maintenance support
- First problem analysis
contact:
- Ask your manager or IT department about the administrator
Stage 2: IT help desk/IT support
Responsible for:
- Technical issues (browser, network)
- Login issues (Microsoft Azure AD)
- hardware problems (terminals)
- Performance issues
- server failures
contact:
- Hotline (phone number of your IT department)
- Your organization's ticket system
- Self-service portal
---
Stage 3: DEXIOS manufacturer support
Responsible for:
- Complex technical issues
- Software bugs
- In-depth configuration questions
- Feature requests
contact:
- Through administrator or IT department
- Direct contact usually only for administrators
- Support contracts regulate availability
If possible, please include the following:
Tenant name
How long has the problem existed?
Does it always occur sporadically?
Replication steps
error messages (text/code) and screenshot
your contact details
How can I provide feedback?
Feedback channels:
1. Contact administrator:
- Who: Your DEXIOS administrator
- For: suggestions for improvements, bugs, feature requests
- How: email, phone, in person
- Administrator collects feedback and forwards it to manufacturers
2. IT help desk:
- Who: Your IT Support Department
- For: Technical issues, bugs
- How: ticket system, email, telephone
- IT forwards relevant feedback
3. Internal feedback channels:
- Some organizations have internal feedback tools
- Ask administrator
What you should report:
Errors (bugs):
- What did you want to do?
- What happened? (exact error message)
- Step-by-step reproduction
- Screenshot helpful
Suggestions for improvement:
- What would you like to have improved?
- Why is that important?
- What would be the benefit of the improvement?
- Formulate concretely
Feature requests:
- Which feature is missing?
- Which use case would it solve?
- How do you imagine the function?
Usability issues:
- What is unclear or difficult to use?
- Where are you having trouble?
- What would make it easier?
Positive experiences:
- What works well?
- Which features are particularly useful?