User Groups
The section presents working with permissions of user groups.
Add Axidian user group
- Navigate to the User Groups section and click Add.
- Fill in the Name and Description fields.
- Click Save.
Add from catalog
- Navigate to the User Groups section and click Add from directory.
- Enter the directory name and click
.
- Select the group and click Save.
Group profile
For each user group, the following are displayed:
- Users — a list of users who are members of the group.
- Permissions — a list of granted permissions for the group to connect to resources.
- Sessions — a list of active, ended, and aborted sessions.
- Events — records of operations related to the group.
Add users to the group
Only for groups created via Axidian Privilege.
To add users to a group:
- Open the user group profile.
- Go to the Users tab and click Add users.
- Select one or multiple users and click OK.
- Confirm the selection and click Add.
Add permission
Open the user group profile.
Click Add permission.
(Optional) Select an organizational unit and users or a group of users.
Select the permission parameter:
Resources — permission is granted to one or more selected resources.
Resource groups — permission is granted to the selected resource group.
Ad hoc resources — permission is granted to any resources with the selected connection type, including resources not registered in PAM.
cautionA special license is required to grant permission to PostgreSQL and MSSQL resources or groups containing such resources. Before creating a permission, add an account from PostgreSQL Server to PAM. When creating a permission, specify this account.
For Ad hoc resources, there is one account for all types of connections. Local account selection is unavailable.
Select account for user connection:
- Select account in PAM — the account under which the user opens a session on the resource.
- Use user account — no account is specified in the permission.
The user enters their account login and password on the resource. In RDP and SSH sessions, it is possible to log in using the current Axidian Privilege user credentials.
Configure Time restrictions and click Next.
Configure Permission parameters and click Next.
Enter a description and click Next.
Check the selected data and click Create.
Synchronize user groups with directory
Only for groups from directory service.
- Open the user group profile.
- Click Sync and confirm the action.
Select policy
- Open the user group profile.
- Click
next to the Policy parameter.
- Select a policy from the list and click Select.
Remove
- Open the user group profile.
- Click Remove.
- Confirm the action by clicking Remove.
To delete multiple groups, in the User Groups section, select the required groups and click Remove.