Add and Import Groups

You can define new groups within Security Manager or import existing groups from Access and Identity Management or Active Directory into Designer.

Add an Access and Identity Management Group

Groups and their associated permissions can be defined in the Security Manager; however, these definitions only take effect if the group name matches an existing group in your Security Provider. While user assignments must be managed through the Access and Identity Management Dashboard, it can still be beneficial to predefine group names and permissions, as these settings will automatically apply once matching groups are imported from your provider.

To create a Group, follow the steps below.

  1. Go to the Home tab and click Security. If Security is not enabled, you will be prompted to enable it. Click Confirm to reopen the project with Security enabled. The Security Manager will open.
  2. In Groups & Privileges, click on the Add button located at the top-left corner.
  3. Type in the Group Name you wish to add.
    Note: A few requirements to keep in mind when creating groups:
    • Group names must be unique
    • Group names are not case sensitive
  4. Click the Check Name button to verify whether a group with the same name already exists in the Access and Identity Management Dashboard.
  5. You may still proceed with adding the group if the name does not yet exist. The privileges will be valid as long as there is a matching name.
    • If no match is found, you can still add the group to the project's security settings, but it must also be added in Access and Identity Management.
    • If a match is found, it already exists in Access and Identity Management and no further action is required.
  6. Click OK.

Import Access and Identity Management Groups

It is also possible to import groups created in the Access and Identity Management Dashboard.

  1. In Groups & Privileges, click on the Import button.
  2. Any groups that have not been added to the project will now be imported.

Add a Active Directory Group

Groups can be defined in Security Manager; however, user assignment must be done through the Access and Identity Management Dashboard.

To create a Group, follow the steps below.

  1. Go to the Home tab and click Security. If Security is not enabled, you will be prompted to enable it. Click Confirm to reopen the project with Security enabled. The Security Manager will open.
  2. In Groups & Privileges, click on the Add button located at the top-left corner.
  3. Type in the Group Name you wish to add.
  4. Click OK.

Import Active Directory Groups

Users from Windows Active Directory can be used to log in to Designer and Runtime. First, they must be imported.

Before you can import an Active Directory user or group, go to Security Manager > General and ensure the Security Provider is set to Active Directory.

Important: The Designer and Runtime Workstations using this feature must be joined to Active Directory.

To import an Active Directory user or group:

  1. In Security Manager, go to Users/Groups > Security Groups.
  2. Click Add.
  3. Type in the Group Name you wish to add.
  4. Click Import.
  5. Select the Object Type to be imported. The default is Groups.
  6. Click Locations... to select where the group is located in Active Directory.
  7. If you know the name of the user or group, enter it and click Check Names to verify.
  8. To search for a user or group, click Advanced.
    1. Enter the Name of the user or group and select whether the entered text Starts with or Is exactly the entered text. Leave blank if you are not searching by name.
    2. Enter the Description of the user or group and whether the entered text Starts with or Is exactly the entered text. Leave blank if you are not searching by description.
    3. Check Disabled accounts to include them in the search results.
    4. Check Non expiring password to include those accounts in the search results.
    5. Enter in the maximum number of Days since last logon to limit the search to more recently logged in users.
    6. Click Find Now and select the your users and groups from the search results to be added. Click OK.
  9. Click OK.

When the user logs into Runtime, they can either enter their Active Directory login information with the username in the format DOMAIN\username. To log in as the currently logged in Windows user, check Use Windows User.