Managing IAM user groups
You can update the members in a group and their permissions from the Group Information page. Use the Status setting to temporarily suspend a group's permissions.
The IAM User Group page displays the following information:
Column |
Description |
---|---|
Group Name | The name of the user group. |
Number of Users |
The number of users assigned to the group. |
Description | The description of the group. |
Updated | The date the group was updated. |
Status | The group's status (Active/Disabled) |
To update group details:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Click the Group Name. The IAM User Groups
> <name> pane is displayed.
- Click Edit.
- Update the Group Name, Status, and Description, and then click Update.
To disable a user group:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Select a group(s) in the list.
- Click Disable. The Permission Changed Confirmation dialog opens.
- Click Yes. The group's Status is changed to Disabled and the members' portal permissions are suspended until you re-activate the group.
To activate a user group:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Click the Group Name. The IAM User Group > <group_name> page is displayed.
- Click Edit.
- From the Status dropdown, select Active.
- Click Update. The group's Status changes to Active and the members' portal permissions are restored.
To delete a user group:
![]() |
You cannot delete a group that has members or a group with Status of Disabled. |
- Go to IAM User Groups.
- Select the user group(s), and click Delete. The Permission Changed Confirmation dialog is displayed.
- Click Yes. The group is removed from the list.
Adding and removing users
Add or remove users from the Users tab in the group details page.
To add users to a group:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Select a user group, and click Add User. The Add User:<group_name> dialog appears.
- Select users from the list. You can filter the list with the Filter Users by Group dropdown, or use the Search field to find a specific user.
- Click Add.
![]() |
You can also add users to a group from the Users tab in the group details. |
To remove a user from a group:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Click the Group Name. The Manage IAM User Group > <group_name> page is displayed.
- Click the Users tab.
- Select the user(s), and then click Remove User. The Remove User from User Group dialog opens.
- Configure the user's portal permissions and click Confirm. If you do not configure the permissions the user will lose access to the portal.
- Click Confirm.
Assigning portal and service permissions to a group
Use the Asset Permissions setting to manage the assets group members can access. Asset Permissions are mapped to the Asset Folders in the Asset Management portal. For information, see FortiCloud Asset Management Guide > Organizing assets.
To update portal and service permissions:
- Go to IAM User Groups. The IAM User Groups pane is displayed.
- Click the Group Name. The Manage IAM User Group > <group_name> page is displayed.
- Click the Group Permissions tab.
- In the Portal Permissions area, click the Edit button next to an asset.
- Configure the user portal permissions:
-
Admin
-
Read Only
-
Read/Write
-
SuperAdmin
-
Read Only
-
Recieve Renewal Notification
-
Customer Serivce
-
Technical Assistance
-
RMA/DOA
- Click Confirm.
- Configure the Cloud Management & Services settings.
- Click the plus (+) sign, and select a service from the list.
- Click the Edit button.
- Configure the service permissions.
Admin
Read Only
Read/Write
SuperAdmin
Read Only
- Click Confirm.
Permission Description Allow Portal Access Toggle Yes to grant access to the service. AccessType The Access Type is defined by the portal. For example, the access types for Asset Management are:
Whereas the access types for FortiOS SSO are:
- Click Update.
Permission | Description | ||
---|---|---|---|
Allow Portal Access |
Toggle Yes to allow access to a portal. |
||
Access Type |
The Access Type is defined by the portal. For example, the access types for Asset Management are: Whereas the access types for FortiOS SSO are: |
||
Additional Permission |
Additional permissions vary depending on the portal. Asset Management: FortiCare (Read Only or Read/Write)
|