- 23 May 2023
-
DarkLight
-
PDF
Groups
- Updated on 23 May 2023
-
DarkLight
-
PDF
This section captures how users and groups are created and assigned in IAP. Group management and configuration is also explained.
- Users are assigned to external groups within the external AAA system. Users cannot be assigned to external groups using IAP.
- An external group is an account that comes from an external AAA System such as LDAP. An external group cannot be created within IAP.
- An IAP group is an account created within the IAP system. Users are assigned to IAP groups through Authorization.
Note: If
User1
is a member ofGroup1
and starts a job, andUser2
is not a member ofGroup1
, thenUser2
will not be able to see the job.
Managing Groups
External groups cannot be created within IAP. Instead, IAP will create the external group record once it has been learned from the AAA system.
To manage groups within IAP:
- Login to IAP as an administrator (a user with the
Pronghorn.admin
Role). - Navigate to Admin Essentials > Quick Start > Authorization.
- SelectGroups. A list of all defined groups and their provenances is displayed.
- Locate the group in the list. You can filter the list by typing in the Search Groups field.
- Select the group in the list to view or edit.
- Edit the description as desired.
- Edit roles and groups as desired.
- Click Save to finalize your changes.
Figure 1: Edit Group Roles
Configuring Group Membership
An IAP Group may be added or removed using the Authorization. IAP groups and external groups can be given membership to an IAP group. In contrast, neither group can be given membership to an external group.
To change group membership:
- Login to IAP as an administrator (a user with the
Pronghorn.admin
Role). - Navigate to Admin Essentials > Quick Start > Authorization.
- Select Groups. A list of defined groups is displayed.
- Locate the group in the list. You can filter the list by typing in the Search Groups field.
- Select the group in the list to view or edit.
- From the Edit Group modal, select Groups .
- Add or remove group membership by selecting the checkbox.
Identifying Group Members
A members list identifies the users and groups that are direct members of a Group.
- Navigate to the Edit Group modal.
- Locate the Members list (tab). There is no indicator for inherited memberships.
Deleting a Group
⚠ Caution: This is a hard delete. Deleting a group will remove the role from all Users and Groups assigned to it.
Only IAP Groups can be deleted.
- Select Groups from the Authorization menu.
- Locate the group you wish to delete. You can filter the list using the filter fields in the column header.
- Click the stacked dots menu icon and select Delete.
- Confirm the deletion.