Home > System > Permissions > Create Permission Groups

Export to PDF

Create Permission Groups

Permission groups are managed in the Permission groups tab. To define the permissions of a group, you can either assign an existing role to the group or customize the available pages and permissions for the group. Apart from creating permission groups all from scratch, you can also copy permissions from existing groups to create new groups.

Create a New Permission Group

To create a new permission group, complete the following steps:

  1. Click Create to enter the Create permission group page.

  2. Complete the basic group information, including:

    • Group name

    • Description

    • Expiration – Select whether the permission group Never expires or Select an expiration date. You can select either an exact expiration date or a time range after which the group will expire.

    • Assignment – Select the group permission assignment.

      • To customize the permissions of this group and manually select all available pages and actions, click Customized assignment.

      • To assign existing EnPower roles to this group, select Role assignment.

    • Roles – If Role assignment was selected as the group’s assignment approach, select the roles to assign to this group.

  3. In the Members step, click Add to add members to the permission groups. On the Add users/groups panel, select the tenant first then search for the user or group to add. After validation, the users/groups will be added.

    *Note: If the user or group cannot access AvePoint Online Services, the user cannot be added to the permission group. You can remove the user or group or contact your administrator to add the user or group to the AvePoint Online Services user list.

  4. Configure the data source of the permission group’s manageable objects, including:

    • Containers and Tenants – Click Add to add containers or tenants for this permission group. Assigned permissions will only be available when containers of the corresponding object type or tenants are assigned to the group.

    • Advanced settings

      • Domains - Specify the available domains of your Microsoft 365 cloud tenants for the permission group members to select when they are creating or editing objects. By default, Do not designate specific domain is selected, making the available domains for this group the ones related to the selected containers. You can also Specify same available domains for all object types or Specify individual available domains for each object type.

      • Organizational units – If you have connected your on-premises Active Directory to EnPower and have assigned the permissions for managing on-premises resources to this group, you need to select the available organizational units for the permissions group members to select when they are creating or editing the on-premises resources. You can Specify same available domains and organizational units for all on-premises object types or Specify individual available domains and organizational units for each on-premises object type.

    Click Save to create the group if EnPower roles were assigned to this group. For a customized assignment group, click Next to proceed.

  5. In Reports, grant report-related access and management permissions. Click the Icon: Expand. icon to expand the permission lists under each object type and each report page and select individual permissions to grant to the group. To grant all permissions to this group, select the report name or object type.

    *Note: If action permission with the Tenant-level or Tenant-scope tag is selected, group members will be able to create objects or access data in the entire tenant, outside their manageable containers.

    Click Next to proceed.

  6. In Dashboards, select the accessible dashboards and available dashboard charts for this permission group. By granting permission to specific dashboard, available charts on the dashboard will be able to be added to or removed from both built-in dashboards provided by EnPower and custom dashboards created by users. Click Next to proceed.

  7. In Workflows, select the available trigger events and workflow permissions for this permission group.

  8. Click Save to create the permission group.

Create a Permission Group by Copying Permissions

By copying an existing group, a new group will be created with all members and settings copied from the source group. During the creation process, you can make edits based on your requirements without having to complete all setups from scratch. This is applicable when you want to create a new group with only a few different settings from an existing one.

To create a permission group by copying permissions from existing groups, complete the following steps:

  1. Select the permission group you want to copy permissions from.

  2. Click Copy permissions. You will be navigated to the Create permission group page.

  3. Complete the group information and settings. The group members, manageable service types and containers, and permissions have all been copied from the selected group.

  4. Click Save to create the permission group.