RapidIdentity Product Guide

Group Policies

The Group Policies section of the Folders module allows administrators to define policies specific to a group, set a group folder, and define folder template actions.  The Group Policies layout and functionality is similar to User Policies. To access the Group Policies, navigate to the Folders module and click on Group Policies.

Group_Policies_Main.png

Once a policy has been added, there are three main tabs that assist in defining a policy. More details on these fields are listed below.

General

Group Folder

Actions

Policies_Tabs.png

General

The General menu contains fields to characterize a Group policy.

Table 348. General Tab Fields

Field

Description

Enabled

This checkbox will activate the policy when checked. If this box is left empty, the policy will remain inactive.

This checkbox is disabled by default.

Description

This optional input field allows for a brief description of the policy.

Group Base DN Filter

This input field defines the group's DN base filter that the policy will apply to using the appropriate distinguished name (DN) filter. This will refer to the container that holds the Groups to which the policy applies.

The magnifying glass glass.png to the right of the field opens the LDAP directory tree to allow the administrator the ability to locate and select the DN or Group.

Include Sub-Containers

This checkbox will apply the policy to all containers under the base container when checked. If this box is deselected, the policy will only apply to the base container.

This checkbox is enabled by default.

Group LDAP Filter

This input field defines the group(s) that the policy will apply to using the appropriate Lightweight Directory Access Protocol (LDAP) filter.

The magnifying glass glass.png to the right of the field opens the LDAP criteria builder window to allow the administrator the ability to build the LDAP Filter.

Excluded Groups

This field allows groups to be excluded from the policy.



Group Folder

The Group Folder menu contains fields that define the Template and UNC Path of the policy it relates to.

Table 349. Group Folder Fields

Field

Description

Template

This dropdown field allows the selection of a specific template to be assigned to the Group Folder.

This field is required.

UNC Path

This input field defines the location of Group Folder.

The magnifying glass glass.png to the right of the field allows the administrator the ability to search and select the attribute.

The required format must include the path with "%attr%"at the end, where "attr" is the name of the attribute from the object in which the folder is being created.

Example

\\servername\Users\%employeeID%

This example defines the UNC Path with the employeeID as the Group folder attribute.

This field is required.

Create Group Share

This checkbox allows the Group Folder to be shared privately when checked.

This checkbox is disabled by default.

Hidden

This checkbox will determine if the Home Folder will be hidden from a group or multiple groups. The value of the checkbox cannot be selected until the Create Private Share checkbox is selected.

This checkbox is disabled by default.

ACL

Once the Create Group Share checkbox is checked, the ACL (Access Control List) can be populated to set permissions.



Actions

The Actions menu allows administrators to define the folder template actions upon Active Directory interaction.

Table 350. Actions Fields

Field

Description

Allow Takeover of Unassociated Existing Folder

When enabled, this checkbox will allow a takeover of the unassociated existing folder.

This checkbox is disabled by default.

Delete Group Folder

This input field defines the number of days when the Group Folder is deleted after the group is deleted.

The checkbox is enabled by default, and the input field is disabled if the checkbox is de-selected.

Move Existing Group Folder

This input field defines the maximum GB allowed for a move. For unlimited GB allowance, leave this field blank.

The checkbox is enabled by default, and the input field is disabled if the checkbox is de-selected.

Move Allowed Times

This section allows the administrator to select times and days in which folders will be allowed to be moved.

The checkbox grid displays the time slots as 12 AM through 11 PM and the days as Sunday through Saturday.