Groups are defined subsets of users or groups. Groups can be created manually or imported. They are also created automatically when importing users.
Assign a role
When you edit or create a new group, you need to assign one or more roles. Assign roles to a group to give the members specific permission on the system e.g. give the student group the member role. And create a group teachers with the moderator role.
Select a role in the left column and click on >> to assign the role to the (new) group. Click Add to commit your work, or continue with Members to add members.
Select the tab members and click Add to add members or groups to this group.
Select group or user and start typing in the Name field. Existing groups/members will be suggested.
Download Secret key
When combined with the permission Download group's secret key the interface will show an additional feature to download a key. This secret key can be used when setting up communication with other applications via the Presentations 2Go API.
Create or download an example csv file in the following format to bulk import/create users into groups.
Use the isgroup parameter to create groups into groups. Groups that are not yet registered will automatically be created.
In saml mode identifying users based on username or email address might not always uniquely identify the user. That’s why we use Username, Email address and eduPersonTargetedID. This means you can use either username, or username and email address or eduPersonTargetedID and username and email address in the username column.
NOTE: Restrict the amount of entries. Too many entries will cause time-out issues. Large lists are better processed automatically.
If you are in a federated environment and allow access to users from other organizations en you cannot guarantee that these users one unique emailaddress per organization (for example if organisations allow Hotmail address), you should also use EdupersonTargetedID in your csv files.
NOTE: SAML authenticated servers need to add additional information when removing users in bulk. Since the unique username is now a combination of 3 attributes.
Automatic groups in SAML2
If you use SAML2 as authentication provider, you can use the eduPersonAffiliation attribute to grant membership of groups based on the affiliation. Affiliation attributes often used (eg. In OpenConext) are “Employee” and “Student”.
When you create a group affiliation.Employee, a user logging in with the eduPersonAffiliation attribute set to Employee, will automatically become member of that group. Similar you can use the group affiliation.Student to detect users with the eduPersonAffiliation attribute set to Student.
Like Authenticated Users and Anonymous users groups, membership of that group is automatic and you don’t have to add users in that group.