Enter the following main data of a group.
| Property | Description | 
|---|---|
| Name | Name of the group. | 
| Canonical name | The canonical name is generated automatically and should not be changed. | 
| Group type | Detailed name of the group type. | 
| Distinguished name | The distinguished name is determined using a template and must not be changed. | 
| Object GUID | Unique ID used for managing the object in the target system. | 
| Display name | Name for displaying the group in the user interface of One Identity Manager tools. | 
| Target system | Name of the target system. | 
| Container | Container in which to create the group. | 
| Service item | Service item data for requesting the group through the IT Shop. | 
| Risk index | Value for evaluating the risk of assigning the group to user accounts. Set a value in the range 0 to 1. This input field is only visible if the QER | CalculateRiskIndex configuration parameter is activated. For more information about risk assessment, see the One Identity Manager Risk Assessment Administration Guide. | 
| Category | Categories for group inheritance. Groups can be selectively inherited by user accounts. To do this, groups and user accounts are divided into categories. Select one or more categories from the menu. | 
| Description | Text field for additional explanation. | 
| IT Shop | Specifies whether the group can be requested through the IT Shop. If this option is set, the group can be requested by the employees through the Web Portal and distributed with a defined approval process. The group can still be assigned directly to hierarchical roles. | 
| Only for use in IT Shop | Specifies whether the group can only be requested through the IT Shop. If this option is set, the group can be requested by the employees through the Web Portal and distributed with a defined approval process. Direct assignment of the group to hierarchical roles or user accounts is not permitted. | 
| Read-only memberships | Specifies whether memberships are read-only. For example, dynamic groups. The memberships are regulated by the target system. Manual changes to memberships in One Identity Manager are not permitted. | 
