Creating Users / Extensions
- Creating Users
- Call Forwarding
- Boss-Secretary
- Forwarding Rules Evaluation Priority
- Call Recording Protection
- Adding Phones to a User
- Step 1: Add The Phone to the Extension
- Step 2: Router Phone, SBC or LAN?
- Step 3: Connect the Phone
- Configuring an IP Phone Manually
- Importing and Syncing Users
- Importing and Syncing users from Microsoft 365
- Importing users from a CSV file
- Securing your User Accounts
- Configuring Google or Microsoft Single Sign-On (SSO)
- 2FA - Two Factor Authentication
- See Also
Creating Users
To set up your users in 3CX:
- Go to Admin > Users.
- Click on the Add User button
- Enter the details for your new user in the General tab:
- Extension: the next available extension number is pre-populated; you can change this to any valid extension number that is not already in use
- Email: the email address is important for delivering essential notifications to your user, such as welcome emails with login instructions and voicemail notifications
- First Name and Last Name: to label and identify the user to other users
- Mobile Number: to forward calls to mobile when the user is away from his desk
- Outbound Caller ID: so when the user calls out, the recipient of the call gets the correct number to call the user back
- Role: to specify what rights the user has over system functionality and visibility of other users; this can range from the highest-level role System Owner, which allows any actions including elevating rights for other users, to the lowest-level role User, which allows only access to settings relating to the user's own calls and data; you can get more information about Access Roles here
- Main Department Membership:
- if the user is in a department that enables Publish department information to all extensions, the user gets to see status information for all users in the same department
- this department will dictate the office hours, the time zone, and the language for the user, even though office hours and language for each user can be specifically set to override the department settings
- best practise strongly recommends that a user is a member of only one department
- in a Multi-Company system, a user can only be a member of one department
- read more about Departments here
- Assigned DID number(s): select a DID number you want to assign to this user; typically this will be the same value of the user's Outbound Caller ID to ensure that returned calls are correctly routed.
- Starting from V20 Update 10, users can select any assigned DID for outgoing calls in the 3CX Web Client, PWA, or apps. Enable "Allow Users to Select Outbound Route & Caller ID" in Admin > System > Options > Apps.
- In the remaining tabs you can configure each user’s 3CX Talk link, Call Forwarding rules, Schedule (for working hours), IP Phone, BLFs, Voicemail, View rights, and other Options
- Click the Save button to create the new user
- Each new user created will receive a Welcome Email with account details
Call Forwarding
Call Forwarding rules define how 3CX routes calls based on an extension’s status. Call Forwarding can be configured:
- from Admin > Users > [select user] > Call Forwarding
- from the Web Client in "Settings → Call Forwarding"
Boss-Secretary
You can configure Boss-Secretary for any PBX user in Admin > Users > [select user] > Call Forwarding > Boss-Secretary.
- Once you Allow Boss-Secretary, you can:
- Assign a Secretary/PA; you can select a regular user's extension number, or an AI Personal Assistant
- Select the hours during which the designated Secretary will screen calls for the boss
- Select whether the Secretary will screen internal calls, external calls, or all calls
- Define trusted Allowed Direct Callers who can reach the Boss without having the Secretary screen the calls
- Users can then Activate/Deactivate the Boss-Secretary function for themselves and edit their personal settings using the pencil Icon in their status panel.
Forwarding Rules Evaluation Priority
Note: Boss-Secretary rules have the highest priority, overriding all other Forwarding rules and Forwarding Exception rules. This guarantees consistent and predictable call routing. The Forwarding Rules are evaluated with the following priority:
- Allowed Direct Callers bypass all Forwarding or Boss-Secretary rules and ring the Boss directly regardless of any other forwarding logic
- Boss-Secretary logic is evaluated next; calls are routed to the Secretary/PA as defined
- If a call is forwarded by the Boss-Secretary rules, then no other forwarding rules are applied; this prevents chaining or conflicts with other rules
- If none of the Boss-Secretary rules are triggered, the system proceeds to evaluate the regular Call Forwarding Exceptions
Call Recording Protection
If your PBX or Department has Call Recording, you can protect calls made or received by selected extensions from being recorded by other internal call parties. To do so, enable "Prohibit allowing others to record your calls" in Admin > Users > [select user] > Options.
Adding Phones to a User
Provisioning a phone for a user is essentially a 3-step process. For older devices, manual configuration is also possible.
Step 1: Add The Phone to the Extension
Go to Admin > Users:
- Select the user you want to add a phone for.
- Click on the “IP Phone” tab. Click “Configure a phone” to add a phone.
- Now select your phone model from the dropdown menu.
- Enter the phone’s MAC address without dashes or colons, and click “Next”.
Step 2: Router Phone, SBC or LAN?
- If 3CX is on the cloud, you must use a router phone or SBC:
- If it is not a router phone you need to specify one or an SBC.
- If the phone is a router phone you can configure it to connect directly if you prefer.
- If 3CX is on premise or self hosted, you have an additional option, you can select “Local LAN/VPN”.
- Click “Add Phone” to save the phone configuration for this extension.
Step 3: Connect the Phone
3CX will now create provisioning information for the phone and make these available on the provisioning URL. The phone must connect to this URL to retrieve its configuration information and authentication details. You have the following options:
- RPS - Connect the phone to the network within 14 days. If it is already connected, restart it. The phone will be configured automatically and restarted.
- PNP - If 3CX is on premise or connected via SBC, you can connect the phone to the LAN and look for it in the PNP dialog (Admin Console > Phones > PnP Phones). Right click and assign it to the extension you configured above.
- Alternatively you can login to the phone's webUI and enter the URL manually. You can also use DHCP option 66.
Configuring an IP Phone Manually
Some older phones cannot be provisioned automatically via 3CX. These phones must be configured manually using an auth ID, a password and the FQDN of the 3CX server (if the phone is on the local network) or the IP of the SBC or router phone (if the phone is in the cloud).
- Go to Admin > Users > Your User > IP Phone. Click "Configure a phone" to add a phone.
- Check the box "I will configure the phone myself".
- If the phone is remote, choose the router phone behind which this phone will connect.
- Now a dialog will show the configuration details:
- Extension Number
- Authentication ID
- Password
- 3CX FQDN and Port.
- If the phone is remote, the SBC or Router phone’s IP address and Port will also be shown.
- Now login to the phone’s web interface and insert these details. We have documented these last steps for the most popular legacy phones:
- Avaya 9601, 9608G, 9611G, 9621G and 9641G
- Fanvil X1, X3, X5, C400, C600 and iW30
- Grandstream GXP IP phones: GXP 1160, 1165, 1400, 1405, 1450, 2100, 2110, 2120, 2124
- Polycom VVX Series (EOL): 300, 310, 400, 410, 500, 600
- Snom 300, 320, 360, 370, 820, 821, 870 and Meeting Point
- Yealink T19P, T20P, T21P, T22P, T26P, T28P, T32G, T38G
Importing and Syncing Users
Importing and Syncing users from Microsoft 365
- If you have Microsoft 365, you can import extensions and automatically sync users when you add or delete Microsoft 365 users.
- This functionality is not available in Multi-Company mode; more info in the Microsoft 365 Integration guide.
Importing users from a CSV file
You can import a batch of extensions from a CSV file / Spreadsheet. Download a sample spreadsheet import file here. You can see the full list of importable fields here.
Securing your User Accounts
Configuring Google or Microsoft Single Sign-On (SSO)
You can allow users to access 3CX using SSO from either Google or Microsoft. See these guides to configure SSO for Google or Microsoft.
Note that Microsoft SSO is NOT available in Multi-Company mode.
2FA - Two Factor Authentication
You can enable 2 factor authentication on accounts.
This will force users to enter an additional code besides their email and password. 3CX 2FA supports popular authenticators from:
See Also
- Configuring IP Phones
- Discover and assign phones on the local or SBC network with PnP Phones.
- Configure a DECT phone and assign handsets with Configuring a DECT Phone.
- Mass Deploy 3CX PWA App for Terminal Server Users
- Work remotely with Android and iOS apps
- Android App: No new call notifications - PUSH Troubleshooting guide
- How to Configure Google SSO
- Microsoft 365 Integration
- Import Extensions in Bulk by CSV
- See more about access roles in the Web Client
- Setup Call Forwarding as a User
Content applies to Version: From V20 U10 - Edition: AI, Pro, Basic, SMB - Deployment: HostedBy3CX, OnPremises, SelfHosted
Last Updated
This document was last updated on 16 September 2026
