Groups can be assigned directly or indirectly to identities. In the case of indirect assignment, identities and groups are arranged in hierarchical roles. The number of groups assigned to an identity is calculated from the position in the hierarchy and the direction of inheritance.
If you add an identity to hierarchical roles and the identity owns a user authenticated user account, the user account is added to the group. Prerequisites for indirect assignment of identities to user accounts:
- Assignment of identities and groups is permitted for role classes (departments, cost centers, locations, or business roles).
- The Group authenticated option is not set in the user accounts.
- User accounts are marked with the Groups can be inherited option.
- User accounts and groups belong to the same site collection.
Groups can also be assigned to identities through IT Shop requests. So that groups can be assigned using IT Shop requests, identities are added to a shop as customers. All groups assigned to this shop can be requested by the customers. Requested groups are assigned to the identities after approval is granted.
Detailed information about this topic
- Assigning SharePoint groups to departments, cost centers and locations
- Assigning SharePoint groups to business roles
- Assigning SharePoint user accounts directly to a SharePoint group
- Assigning SharePoint roles to SharePoint groups
- Adding SharePoint groups to system roles
- Adding SharePoint groups to the IT Shop
- Adding SharePoint groups automatically to the IT Shop
- One Identity Manager Identity Management Base Module Administration Guide