Group/Member of tab

In the Member of tab, you enter a group as member of one or several groups.

Select the User management area.

Click on the Properties button in the toolbar.

Important information

The groups where this group is member will be displayed in the upper part of the tab. When a group is selected, the rights of the group in this group are displayed on the lower part of the tab.

By assigning one group as member to another group, hierarchical groups are created.

The rights of a user are furthermore defined by his membership in groups. If a user has different rights in different groups, these rights are added together. A user then has the sum of all his or her rights; in other words, the highest rights from all his or her memberships.

Users view group members in the Select participants window. Different hierarchical groups are considered.

Cycles in hierarchical groups result in a unintended transfer of rights and are thus not allowed in CAS genesisWorld. A cycle is a loop in a hierarchy, for example, group A contains group B, group B contains group C and group C contains group A.

Cycles occur for example when working with Active Directory integration or a damaged database.

Hierarchical groups are checked for cycles upon each start of the Application Server. If the system finds a cycle, you (the administrator) will be notified the next time you log on to the Management Console. All hierarchical relationships between the groups will then be ignored.

Whether a cycle has been created or not is checked when creating hierarchical groups. If a cycle is created when changing group members, an error message is displayed and the change will not be performed.

With the Active Directory Integration, hierarchical Windows groups can be imported to CAS genesisWorld. Active Directory Services also displays organizational units as CAS genesisWorld groups and therefore, cycles may occur automatically.

Functions in the Member of tab

Select the users you want to assign as members of the current group.

The user is no longer displayed in the upper part of the Membership tab.

Now, on the lower part of the tab the access rights of the user in the group you are editing are displayed.

Please also note the settings which are defined with the Activate access rights depending on group membership option on the Access rights folder of the User Management area.

Domain-wide groups are not an option with hierarchical groups.

See also

The User Management module: Synchronization

Access rights levels