Map Group to Domain Security Group

You can map a domain security group to the ERA Server and allow existing users (members of these domain security groups) to become ERA Web Console users.

icon_details_hoverNOTE

This feature is only available for systems with Active Directory. It cannot be used with LDAP.

To access the Mapped Domain Security Group Wizard, navigate to Admin > Access Rights > Mapped domain security groups > New, or simply click New when the mapped domain security group is selected in the tree.

admin_map_group_domain_security

icon_section Basic

Domain group

Enter a Name for the group. You can also enter a group Description. Select Home Group. This is static group where all objects created by users from this domain group will be automatically contained. This domain group will be defined by a Group SID (security identifier). Click Select to select a group from the list and then click OK to confirm.

Account

Enabled - Select this option unless you want the account to be inactive (if you intend to use it later).

Autologout (min) - This option defines the idle time period (in minutes), after which the user is logged out of Web Console.

Email contact and Phone contact can be defined to help identify the group.

icon_section Permission set

Assign competences (rights) for the users from this group. One or more permission sets can be assigned. You can use a pre-defined competence:

Reviewer permission set (read-only rights for the All group)

Administrator permission set (full access to the All group)

Server assisted installation permission set (minimal access rights required for server assisted installation)

Custom permission set

Each permission set provides permissions only for objects contained in the Static Groups selected in the permission set. User without any permission set will not be able to log in to the Web Console.

validation-status-icon-error WARNING

All pre-defined permission sets have the All group in the icon_section Static Groups section. Be aware of this when assigning it to a user. Users will have these permissions over all objects in ERA.

icon_section Summary

Review the settings configured for this user and click Finish to create the group.

Users will appear in the Domain Users tab after they first log in.