Skip to main content

Identity and Access Management: Groups

Assigning roles to groups in Omnissa Cloud Services is more efficient than assigning the same permissions to individual users one at a time. As an Organization Owner user, you create groups and determine the members that make up your groups and what roles they are assigned.

You can also edit groups after they are created or added. As your Organization expands and changes, add or remove members from your groups.

There are two types of groups available in Omnissa Cloud Services – custom groups and enterprise groups. Custom groups can be shared with other Organizations. Enterprise groups can be nested in custom groups.

Custom Groups

You create custom groups by entering a name and a description, adding members, and then assigning roles for the Organization and its resources. For example, you can create a custom group and give it an Organization Member role to your Organization and a support role, and read-only access to specific services in the Organization. Custom groups can also include enterprise groups.

For custom groups, you can edit the name and description, add or remove members, and change the role assignment of the group.

Shared Groups

When you create a custom group, you can decide if you want to make it shared or not. As an Organization Owner, you associate the shared group with other Organizations which allows the members of the shared group to be assigned roles in the associated Organizations and get access to services without invitation from the Organization Owners.

Service roles assigned to shared groups are Organization-specific. The Organization Owners from the associated Organizations import the shared group and assign roles to the group within their own Organizations. To import a shared group, the Organization Owners must know the group name or ID.

Only the Organization Owner of the source Organization – the Organization in which the shared group was created – can modify the members of the group or remove it. Removing a shared group from an associated Organization does not delete it and it can be added back later. See how to manage shared groups.

Enterprise Groups

Enterprise groups are groups synced from your corporate domain. After you federate your corporate domain with Omnissa Cloud Services, your enterprise groups are available for you to use in your Organization. See how to assign roles to enterprise groups.

For enterprise groups, you can only change the role assignment of the group. You cannot add or remove members from enterprise groups in Omnissa Cloud Services, but you can assign them roles for the Organization and its resources, and add them to custom groups.

Nested Groups

Adding a group to another group is called nesting. Here's what you need to know about nested groups:

  • You can nest an enterprise group in a custom group.
  • Nested groups can hold a combination of roles; roles assigned directly to the enterprise group and the roles assigned through the custom group.
  • You can edit the roles of a nested enterprise group or add additional roles, but you cannot remove the roles inherited from the custom group.
  • You cannot nest a custom group in another custom group.

As an Organization Owner, you can also edit groups after they are created or added. For custom groups, you can edit the name and description, add or remove members, and change the role assignment of the group. For enterprise groups, you can only change the role assignment of the group.

As an Organization Owner you create groups, manage the groups, and as your Organization expands and changes add or remove members from your groups.

Note: When you make changes to groups, it may take up to 30 minutes for the changes take effect in the Organization.

How do I create a new group

As an Organization Owner user, you can create new groups in your Organization and assign the group Organization and service roles. These groups are called custom groups.

  1. On the Cloud Services Console, select Identity & Access Management > Groups.
  2. Click Add Groups.
  3. Select Create a new group and click Continue.
  4. Enter a name and a description for the group.
  5. If you want to share the group with other Organizations, click Add Organizations.
    1. Select the Organizations that you want to share the group with: either type the Organization ID for each Organization or make a selection from the list of Organizations displayed in the pop-up window.
    2. Click Add.
      Note:When you create a custom group that is shared, the Organization Owners of the associated Organizations can assign roles to the group in their Organization.
  6. Click Add Members to add members to your group, add then click Add.
    Members can be enterprise groups and users. You can choose to skip this step and add members after you have created the group.
  7. Assign the group access to the Organization by selecting an Organization role.
  8. Assign the group access to services by clicking Add service access and selecting a service and the roles you want to assign to the group for this service.
  9. To add access to an additional service, click Add service access.
  10. Click Create.
    The group is added to the list of groups on the Identity & Access Management page.

How do I assign roles to enterprise groups

If your domain is federated with Omnissa Cloud Services, you can select groups from your corporate source domain and assign them roles in your Organization. These groups are called enterprise groups.

Enterprise groups are groups synced from your corporate domain. You can assign roles to more than one enterprise group at a time, and view the members in a selected group. The members of the group you assign can hold several roles:

  • Organization role: A role within the Organization - Organization Owner or Organization Member. To see the privileges assigned to each of these roles, see How do I manage roles and permissions.
  • Service role: A role within one or more Omnissa Cloud Services. Each cloud service has its own specific roles. For more information, refer to the documentation of the relevant Omnissa Cloud Service.
  • Depending on your customer profile, you might also view the Managed Service Provider role which allows users to query the cloud service APIs for customer usage and data. If you assign this role to members of a tenant Organization, they will have access to all the data within the Organization.

Procedure

  1. From the Cloud Services Console main menu, select Identity & Access Management > Groups.
  2. Click Select groups from your source domain and then click Continue.
  3. Search for the enterprise groups to which you want to assign roles.
  4. Assign the group an Organization role.
  5. Select a service, and then assign the group one or more roles in the service.
    When you select a service, the service default role appears. Click the role to select a different role.
  6. To give the group access to another service, click Add Service Access, and assign a role.
  7. Click Add.
    To send an email to users with the Organization Member role, select the check box. Users with the Organization Owner are automatically sent an email.

How do I manage shared groups

When an Organization Owner user creates a custom group and associates it with other Organizations, the group becomes shared. The Organization Owners of the target Organizations receive and email invitation from the source Organization's Owner to import the shared group and assign service roles.

As an Organization Owner receiving the invitation to import a shared group created in a different Organization, you assign service roles for the shared group while importing it to your Organization.

You can distinguish imported shared groups from shared groups created in your Organization by their label.

The users of the shared group you imported can access the services in your Organization according to the roles you assigned to the group. This allows cross-Organization access to services at the group level and removes the need to send individual invitations to each user.

Important: Shared groups imported from other Organizations cannot be edited. You can edit the roles you assign to the shared group or remove the group from your Organization.

Prerequisites

You must know the name or the Organization ID of the source Organization that created the shared group you want to add.

Procedure

  1. On the Cloud Services Console, select Identity & Access Management > Groups.
  2. Click Add Groups.
  3. Select Import groups from other organizations and click Continue.
  4. From the drop-down menu, select the source Organization that created the shared group.
  5. Select the shared group you want to import.
  6. Select an Organization role to assign the selected group access to your Organization.
  7. Click Add service access to assign service roles to the selected group:
    1. Use the drop-down menu to select the service in your Organization you want the shared group to access.
    2. Click the roles box and select the service roles you want to assign to the shared group.
    3. Define the time period for the access. You might choose an end date or provide a non-expiration access.
  8. To add access to an additional service, click Add service access and repeat those steps.
  9. Leave the Send emails to all invited users notifying them of this role assignment checked if you want all users of the shared group to receive invitations to access your service.
  10. Click Import.

Results

The shared group is added as custom remote group to your Organization.

このページは役に立ちましたか?

このトピックについてフィードバックを送信

このトピックは役に立ちましたか?

個人情報や機密情報は入力しないでください。

リンクを生成しています…