Grouper - Create Include/Exclude Composite Groups

Include/Exclude-type composite groups in Grouper were created previously through the "Admin UI", which is no longer available in the new user interface. This tutorial shows how to create Include/Exclude-type composite groups using the new interface.
Layout:
one column
two columns

Step 1

From the web user interface, create the group as you would normally would following the recommendations for naming the group with the appropriate department or service prefix.

Step 2

Only empty groups can be made Include/Exclude Composite groups. So, before adding any members to the group, open the More actions drop-down menu and select Attribute Assignments.

Step 3

In the group's Attribute Assignments page, click on + Assign attributes.

Step 4

Type include in the Attribute name text box and then select etc:legacy:attribute: legacyGroupType_addIncludeExclude from the drop-down menu options.

Step 5

With etc:legacy:attribute: legacyGroupType_addIncludeExclude as the only option in the Attribute name text box, click Save.

Step 6

Verify that the attribute assignment is as follows:

  • Assignment type: Direct assignment
  • Attribute name: legacyGroupType_addIncludeExclude
  • Enabled?: enabled
  • Assignment values: leave blank
  • Attribute definition: legacyGroupTypeDef_addIncludeExclude

Step 7

Browsing back to the folder where the group is located, there should now be intermediate groups that make up the overall group. Please note that membership updates in Include/Exclude-type composite groups CAN NOT be done to the overall group directly. Instead, membership updates should be done to the "includes", "excludes", or "system of record" intermediate groups. The overall group membership consists of members in the "system of record" PLUS "includes" groups MINUS the "excludes" group members.