User Group Assignment of Product Roles
User Groups allow audit administrators to create a named group of users with predefined:
-
Org scope
-
Permissions
-
AOR
"Product Roles" can be assigned to the group.
Create a new user group (or edit an existing group)
TIP: Use a name that is easy to identify what permissions the group is getting "Auditors for ABC Organization" for example
-
View the group
-
Click on the appropriate product tab (A&R / Rounding for example)
-
Choose the role or roles that you wish all group members to have and save
If you wish to see which roles an individual user is assigned (manually or via user group) navigate to the users profile and click on the appropriate product tab. Here, you will see manually assigned roles with a checkbox and user group assigned roles with text indicating which group granted the user the role.
Automatic User Group Membership via Active Directory Mapping (Early Adopters Only*)
With a small update to your SSO configuration, user administrators can indicate if user group membership is set manually or via mapped Active Directory groups.
Once a user group is mapped to Active Directory user groups, each time an Active Directory user logs in, the system will identify their Converge user group membership based on that mapping.
This means that brand new users and changes to existing users can occur exclusively in the organizations Active Directory system without having to setup or modify the users in Converge.
-
Update your SSO configuration (Contact customer support for technical documentation)
-
Add the full Active Directory Group name to the User Group
When users log in, the system will assign membership to any group with matching AD mapping for the user.
* This functionality is only available for early adopters at this time. Please contact customer support if you are interested in participating.
A good first step is for the Converge System Admin to:
- In Converge, go to Users > Groups > click Add Group > give the Group a name, select an Organization, click Create Group
- Go to View the security group in the Groups list
- Click A&R/Rounding tab
- Select the user role/s you want to apply to the group
- Click the Active Directory Mapping tab
- Click Enable Active Directory Mapping
- Click Add AD Group and enter the name of the group as it should be on your Active Directory
- Click Add Group
- Have your AD Administrator/ IT Department setup the Group on the AD side, with the same name you entered in the Group Name box in Converge
It’s best practice to maintain default groups that do not have user roles associated with them. It’s helpful to know that if a user had a user role/s applied to his/her Profile in Converge, then addition or removal from an Active Directory Mapped Group will not add/remove the role/s from his/her Profile. If you want to manage user roles solely through AD Mapped Groups, you might want to use the Bulk User Role Update tool to remove user roles from people’s Profiles. We do not suggest that as an initial step. Please take care to first test with a small portion of users. If you are changing user roles for users, try to give them a heads up some Converge areas might be temporarily unavailable during the window in which you are making changes.
Converge Platform ADFS and SAML Add AD Group Integration ONLY
Converge Platform ADFS and SAML Setup Form UPDATED
Comments
0 comments
Please sign in to leave a comment.