Enter the following general main data.
Property | Description |
---|---|
Distinguished name |
Distinguished name of the group. The distinguished name is determined by template from the name of the group and the container and cannot be edited. |
Name |
Name of the group. |
Display name |
Name for displaying the group in the user interface of One Identity Manager tools. |
Domain |
Domain in which to create the group. |
Container |
Container in which to create the group. |
Administrator |
The group administrator. |
Service item |
Service item data for requesting the group through the IT Shop. |
Business unit |
Business unit to which the group is assigned. |
See also |
Link to another LDAP object. |
Structural object class |
Structural object class representing the object type. By default, containers in One Identity Manager are added with GROUPOFNAMES. |
Object class |
List of classes defining the attributes for this object. By default, containers in One Identity Manager are added with GROUPOFNAMES. However, in the input field, you can add object classes and auxiliary classes that are used by other LDAP and X.500 directory services. |
Risk index |
Value for evaluating the risk of assigning the group to user accounts. Set a value in the range 0 to 1. This input field is only visible if the QER | CalculateRiskIndex configuration parameter is activated. For more information about risk assessment, see the One Identity Manager Risk Assessment Administration Guide. |
Category |
Categories for group inheritance. Groups can be selectively inherited by user accounts. To do this, groups and user accounts are divided into categories. Select one or more categories from the menu. |
Description |
Text field for additional explanation. |
Condition |
LDAP filter for finding memberships in a dynamic group. |
dynamic group |
Specifies whether this is a dynamic group. |
IT Shop |
Specifies whether the group can be requested through the IT Shop. If this option is set, the group can be requested through the Web Portal and allocated by defined approval processes. The group can still be assigned directly to hierarchical roles. |
Only for use in IT Shop |
Specifies whether the group can only be requested through the IT Shop. If this option is set, the group can be requested through the Web Portal and allocated by defined approval processes. Direct assignment of the group to hierarchical roles or user accounts is not permitted. |