Skip to main content

Grouper - Create Include/Exclude Composite Groups

Include/Exclude-type composite groups in Grouper were created previously through the "Admin UI", which is no longer available in the new user interface. This tutorial shows how to create Include/Exclude-type composite groups using the new interface.
Layout:
one column
two columns

Step

From the web user interface, create the group as you would normally would following the recommendations for naming the group with the appropriate department or service prefix.
Create group as normal
Create group as normal
Create group as normal

Step

Only empty groups can be made Include/Exclude Composite groups. So, before adding any members to the group, open the More actions drop-down menu and select Attribute Assignments.
From the More Actions drop down menu, select Attribute Assignments
From the More Actions drop down menu, select Attribute Assignments
From the More Actions drop down menu, select Attribute Assignments

Step

In the group's Attribute Assignments page, click on + Assign attributes.
Click the Assign Attributes button
Click the Assign Attributes button
Click the Assign Attributes button

Step

Type include in the Attribute name text box and then select etc:legacy:attribute:legacyGroupType_addIncludeExclude from the drop-down menu options.
type include then select etc:legacy:attribute:legacyGroupType_addIncludeExclude
type include then select etc:legacy:attribute:legacyGroupType_addIncludeExclude
type include then select etc:legacy:attribute:legacyGroupType_addIncludeExclude

Step

With etc:legacy:attribute:legacyGroupType_addIncludeExclude as the only option in the Attribute name text box, click Save.
click save
click save
click save

Step

Verify that the attribute assignment iis as follows:

  • Assignment type: Direct assignment
  • Attribute name: legacyGroupType_addIncludeExclude
  • Enabled?: enabled
  • Assignment values: leave blank
  • Attribute definition: legacyGroupTypeDef_addIncludeExclude
Verify attribute assignment is correct
Verify attribute assignment is correct
Verify attribute assignment is correct

Step

Browsing back to the folder where the group is located, there should now be intermediate groups that make up the overall group. Please note that membership updates in Include/Exclude-type composite groups CAN NOT be done to the overall group directly. Instead, membership updates should be done to the "includes", "excludes", or "system of record" intermediate groups. The overall group membership consists of members in the "system of record" PLUS "includes" groups MINUS the "excludes" group members.
Example of folder layout
Example of folder layout
Example of folder layout