About internal user groups

Prev Next

An internal user group simplifies the task of granting a collection of user accounts the same access privileges to the OIDC clients registered in your IAM organization. Any existing user accounts known to your IAM organization can be assigned to a user group:

  • Primary users―User accounts defined in your IAM organization.

  • External users―User accounts defined in a different IAM organization that you enrolled in your IAM organization and to whom you assigned roles for accessing your organization.

User group access privileges

A user group's access privileges are a combination of the roles directly assigned to it and the roles directly assigned to its members. Adding a user account to a user group will increase the group's access privileges if the user's directly assigned roles grant privileges that the group does not already have. Removing a user account from a user group will reduce the group's access privileges if the user's directly assigned roles grant privileges that the group does not have through other sources.

Note

Deleting a user group removes access privileges that other users received through their membership in that group.

One system-defined user group

When Trellix creates an IAM organization, a system-defined Organization Owners user group is created. This group contains all users who are also organization owners. Users in this group can access all roles of all assigned products. You cannot modify or delete the Organization Owners user group.