Create User Groups

User Groups in your VPAM server enable you to segment your internal users immediately after the user is created. This initially limits your internal user's access only to applications that their User Group has access to.

Initial Considerations

VPAM usually has two types of Internal Users:

  • System Administrators: A user that can see everything and do everything in the system

  • Standard User: Follows a Least Privileged Access design philosophy and are configured with User Groups and Custom Roles.

The primary function of a User Group is to establish which Application(s) Standard Users are allowed to see and interact with.

IMPORTANT:
Configuring segmentation at a User Group level does not configure the permissions each User Group has. To configure permissions at a Role level, read the best practices on Segmenting Roles.
NOTE:
System Administrator do not belong to any User Groups or User Roles because they have full access to everything.

Suggested Segmentations

Use any of the following recommendations to ensure you implement zero-trust access at the User Group level.

IMPORTANT:
To follow these guides, you must be a System Administrator role or a user with User Group management permissions.

Recommendations

Ensure that you also read the following recommendations when implementing User Groups.

  • DO:

    • Mix different segmentation techniques to ensure granular access and zero-trust implementations.

    • Ensure User Groups are always purpose-driven.

    • Consider creating separate User Groups for Internal User Access, for Approvals, and for Managing Vendor Access.

    • Remember that an Internal User can be assigned to more than one User Group, so layering multiple User Groups may fit your internal organization structure better than aiming for single groups.

    • Continue configuring zero-trust at the Role-level.
      Read the Roles documentation and the Segmenting Roles best practices.

    • Create at least a rough draft of User Groups before proceeding onto User Roles.
      User Groups act as a "first filter" and will affect several permissions inside a User Role.

  • DON'T:

    • Don't skip User Groups! Permissions inside User Roles are affected by User Groups, so tackle these first!

    • Don't feel like you have to create dozens or hundreds of User Groups.
      Some few customers may need that level of granularity, but most do not

    • Don't configure Internal User Groups for any external third-party users.
      Third-Party Users are known as Vendors.