<style> .chartjs-size-monitor { display: none !important; height: 0 !important; overflow: hidden !important; }p { margin: 0; }span.fr-emoticon.fr-emoticon-img { background-repeat: no-repeat !important; font-size: inherit; height: 1em; width: 1em; min-height: 20px; min-width: 20px; display: inline-block; margin: -0.1em 0.1em 0.1em; line-height: 1; vertical-align: middle; } span.fr-emoticon { font-weight: normal; font-family: "Apple Color Emoji", "Segoe UI Emoji", "NotoColorEmoji", "Segoe UI Symbol", "Android Emoji", "EmojiSymbols"; display: inline; line-height: 0; } blockquote { border-left: solid 2px #5e35b1; color: #5e35b1; margin-left:0; padding-left:5px;}blockquote blockquote{ border-color: #00bcd4; color: #00bcd4;}blockquote blockquote blockquote{ border-color: #43a047; color: #43a047;} table.grid{ border-collapse: collapse;} table.grid td, table.grid th { border: 1px solid #ddd;} .fr-fic.fr-dib{ display: block; margin: 5px auto;}.fr-fic.fr-dib.fr-fir{ text-align: right; margin: 5px 0 5px auto;}.fr-fic.fr-dib.fr-fil{ text-align: left; margin: 5px auto 5px 0;}.fr-fic.fr-dii{ float: none; margin: 5px auto;}.fr-fic.fr-dii.fr-fil{ float: left; margin: 5px auto;}.fr-fic.fr-dii.fr-fir{ float: right; margin: 5px auto;}img.fr-dib.fr-fir { margin-right: 0; text-align: right;}img.fr-dib.fr-fil { margin-left: 0; text-align: left;}img.fr-dib { margin: 5px auto; display: block; float: none;}img.fr-bordered { box-sizing: content-box; border: solid 5px #CCC;}img.fr-shadow { box-shadow: 10px 10px 5px 0px #cccccc;}img.fr-rounded { border-radius: 10px; -moz-border-radius: 10px; -webkit-border-radius: 10px; -moz-background-clip: padding; -webkit-background-clip: padding-box; background-clip: padding-box;}</style><p><strong>In this guide we will cover:</strong></p><p><strong>- What are User/Agent Groups?</strong></p><p><strong>- Enable Groups</strong></p><p><strong>- Creating Groups</strong></p><p><strong>- Configure Groups</strong></p><p><strong>- Updating Mappings</strong></p><p><strong>- Access Control</strong></p><p><br></p><p><br></p><p><strong><span style="font-size: 14pt;">What are User/Agent Groups? </span></strong></p><p data-pasted="true">Groups are used to easily assign a set of roles, teams and CABs to a Group of agents and/or users. Groups are used to ease the management of user and agent access. Instead of assigning sets of roles to each agent/user individually, you can assign them to a</p><p data-pasted="true">Group, which implies their roles or membership to teams and CABs. This simplifies administrative tasks and enforcing security best practices.</p><p><br></p><p>Groups are designed to work best in conjunction with an integrated identity provider, but they can also be managed manually within Halo. </p><p><br></p><p><span style="color: rgb(0, 0, 0);">When using Entra and Azure Groups, this can also make management easier. Rather than needing to create numerous mappings for each of the roles/teams/cabs agents/users in a particular azure Group should have, you can import your existing Groups, and have agents/users assigned to them based on who belongs to them in your identity provider. </span></p><p><br></p><p><strong><span style="font-size: 14pt;">Enable Groups</span></strong></p><p>To enable the use of Groups, head to Configuration > Users > enable the "Groups" module using the "+" icon.</p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImNlODJiZTZlLTkzZWMtNDZmOC1hMDVmLTAzYmIxZmFiOTUyYSJ9.0XfcCuqTHO00topCHbqilSe5tzJUqGuPCZ4jLFV6RXw" class="fr-fic fr-fil fr-dib" width="625" style="width: 627px; height: 340.068px;" height="340"></p><p><strong><span style="font-size: 10pt;">Fig 1. Enable the Groups module</span></strong></p><p><br></p><p data-pasted="true"><strong><span style="font-size: 14pt;">Creating Groups </span></strong></p><p>Groups can be created manually or imported from Entra (importing Groups from other identity providers will be supported in future). </p><p><br></p><p>Importing Groups from your identity provider has the added benefit of dynamically updating the Group in Halo based on the Group's member's in your identity provider. If you wish to manage membership using your identity provider, import Groups. If you wish to manage membership from Halo, manually create these. </p><p><br></p><p><strong><span style="font-size: 12pt;">Who can Create Groups?</span></strong></p><p>Agents with the "Is a Halo Administrator" <a href="https://www.usehalo.com/guides/1899" target="_blank" rel="noopener noreferrer">permission </a>will be able to create Groups, however an additional permission is available to allow non-administrator agents to create Groups:</p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImZhOTRmYzJhLWQ2M2ItNDBlMy04OTc3LWI4MWRmZjc0YTM2NiJ9.KwPeGBuh513zeFUqnXwCgM9EnX6pJBRMllZ8YaGry7E" class="fr-fic fr-fil fr-dib" width="576" style="width: 578px; height: 403.54px;" height="404"></p><p><strong><span style="font-size: 10pt;">Fig 2. Permission to allow an agent to create groups</span></strong></p><p><br></p><p>Any agents with this permission will be able to create new Groups manually, but they will not have access to all Group configuration, they will only be able to:</p><ul><li>Create (and name) a Group</li><li>Add members to the Group</li><li>Add User role mappings to the Group</li></ul><p>The rest of the Group configuration is only available to admins. </p><p><br></p><p>This permission does not control if the agent can edit existing Groups, this is controlled by access control (covered later in this guide). </p><p><br></p><p><strong><span style="font-size: 12pt;">Creating Groups Manually</span></strong></p><p>To create a new Group head to Configuration > Users > Groups > New. Name the group and save it. The rest of the Group configuration will be covered in the next section. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImU1YzRlNzYxLTk2ZjgtNGFiZS1hMDY2LTBmYTA3YmQ0M2JkZSJ9.cdMtvGNbK-JGPcA0Iyi0IJUeLWmaH87tTA4prRrajKY" class="fr-fic fr-fil fr-dib" width="1757" style="width: 1759px; height: 432.01px;" height="432"></p><p><strong><span style="font-size: 10pt;">Fig 3. New Group</span></strong></p><p><br></p><p><strong><span style="font-size: 12pt;">Import Groups from Entra</span></strong></p><p>Importing Groups from Entra will import all <span style="color: rgb(0, 0, 0);">your Microsoft and Security Groups from Entra </span>and create each of these as a Group in Halo. The users currently assigned to these Groups in Entra will automatically be added as members to the Group in Halo. Additonally, when the Group members are updated in Entra these changes will be reflected in Halo too. </p><p><br></p><p>Before importing Groups ensure you have successfully connected the<a href="https://www.usehalo.com/guides/1106" target="_blank" rel="noopener noreferrer"> Entra integration </a>and imported your agents/users. </p><p><br></p><p><em><strong>Note: You do not need to have imported agents/users in order to import Gro</strong></em><span style="color: rgb(0, 0, 0);"><em><strong>ups but members will not be able to be assigned to the Group until you have imported agents/users from Entra.</strong></em></span></p><p><br></p><p><span style="color: rgb(0, 0, 0);">Head to the 'Imports' tab of the integration and hit "Import Groups" to begin the import. </span></p><p><span style="color: rgb(0, 0, 0);"><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjU1MWU2ZGM1LWY0ZTItNGFkYy1hNmZkLTE1NmM5Y2EzY2VlNSJ9.Dyed7oqlmzGfx_ftimveSuFhBsMqL5xJh1QX5nGN4B4" class="fr-fic fr-fil fr-dib" width="1316" style="width: 1318px; height: 463.618px;" height="464"></span></p><p><strong><span style="font-size: 10pt;">Fig 4. Import Groups </span></strong></p><p><br></p><p>When importing, each Group in your Entra will be created as a Group in Halo. Only agents/users that already exist in your Halo instance will be assigned to these Groups. Agents/users are matched<span style="color: rgb(0, 0, 0);"> to Groups using their Entra ID (uazureoid for users and uactguid for agents). </span></p><p><br></p><p>When Groups are created via an import only the name and members of the Group are set. The rest of the Group (roles, teams, CAB membership) will need to be configured in Halo.</p><p><br></p><p><strong><span style="font-size: 14pt;">Configure Groups</span></strong></p><p><strong><span style="font-size: 12pt;">Group Details</span></strong></p><p>After you have named the Group you can set whether the Group has a managed Team and/or CAB.</p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImYxMjlkZTBmLTdmOTMtNDEyNC05ZmI1LWIyODI4ZWMxOTM3YSJ9.9KqBNnhs5da1fuijBvpuRSV8MxLLCyruc6S6YbYo6ZM" class="fr-fic fr-fil fr-dib" width="1828" style="width: 1830px; height: 443.989px;" height="444"></p><p><strong><span style="font-size: 10pt;">Fig 5. New Group</span></strong></p><p><br></p><p><strong>Managed Team - </strong>Here you<span style="color: rgb(0, 0, 0);"> can directly link the Group to an existing team to highlight which team this Group is primarily associated with. Choosing "*Create New*" will create a new team upon saving, automating team creation. The team will have the same name as the Group and membership will be inherited from the Group. </span></p><p data-pasted="true"><span style="color: rgb(0, 0, 0);"><strong>Managed CAB - </strong>Here you can directly link the Group to an existing CAB to highlight which CAB this Group is primarily associated with. Choosing "*</span>Create New*" will create a new CAB upon saving, automating CAB creation. The CAB will have the same name as the Group and membership will be inherited from the Group. Created CABs will also inherit the access control of the Group. </p><p><br></p><p data-pasted="true">If a CAB is removed from a Group the Group members will be removed from the CAB too. </p><p><br></p><p><strong><em>Note: Non Administrator agents will not be able to set the "Managed Team/CAB" for a Group. </em></strong></p><p><br></p><p><strong><span style="font-size: 12pt;">Default the creation of a Team and/or CAB for each Group </span></strong></p><p>The settings shown in Figure 5 can be defaulted using the global settings shown in Figure 6. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjM5MjAyOTkxLTEzNDktNDZjYS05NmViLTM3MWZjMGFlZTU3MiJ9.zHWwnLQmVg4k3gWdyFrzqxHa56xkxmnNep0yZGlpB00" width="922" style="width: 924px; height: 386.1px;" height="386" class="fr-fic fr-dii"></p><p><strong><span style="font-size: 10pt;">Fig 6. Automatically create a managed Team/CAB when creating a Group</span></strong></p><p><br></p><p><strong>Automatically create a managed Team when creating a Group - </strong>When enabled, the "Managed Team" field against a new Group will defaulted to be '*Create new*'. This can be leveraged to automate team creation when Groups are imported from Entra. Used when the Group's members should have their own team in Halo. This can also be used to allow non admin agents to create a team when they are creating a Group. If a non-admin agent creates a new Group they will not see the options shown in Figure 5 therefore this setting can be enabled to have a team create automatically each time a non admin agent creates a Group. </p><p><br></p><p data-pasted="true"><strong>Automatically create a managed CAB when creating a Group - </strong>When enabled, the "Managed CAB" field against a new Group will defaulted to be '*Create new*'. This can be leveraged to automate CAB creation when Groups are imported from Entra. Used when the Group's members should have their own CAB in Halo. This can also be used to allow non admin agents to create a CAB when they are creating a Group. If a non-admin agent creates a new Group they will not see the options shown in Figure 5 therefore this setting can be enabled to have a CAB create automatically each time a non admin agent creates a Group. </p><p><br></p><p><strong><span style="font-size: 12pt;">Assign Agents/Users to the Group (Members Tab)</span></strong></p><p>Under the "Members" tab you can see and manage who is assigned to this Group. All the agents/users who are members of the Group will inherit the teams/roles and CABs assigned to the Group. If you have imported your Group from Entra you do not need to set the members manually as these will be imported in line with the members in the Azure group. </p><p><br></p><p>To add a member to the Group manually simply add to the members table. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjliMDM2OWQwLTg1YmYtNDQwYy04OTU2LTE1NDM4MmJhZDZhZiJ9.F265gCnTFJbyWeACZPUqsUUTIXAqbeJzj5n37ZCG-ZU" class="fr-fic fr-fil fr-dib" width="1625" style="width: 1627px; height: 336.953px;" height="337"></p><p><strong><span style="font-size: 10pt;">Fig 7. Members tab</span></strong></p><p><br></p><p>When adding members, simply choose whether to add agents or users then select which agents or users to add. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjFkOGE2MTk4LWI1MmEtNGU4YS04ZWExLTgxMjg2MjJlZDZiNyJ9.RwRq00t48UmxpB_RFGvA6OuRG98St-1n_eCuLKXBEV8" class="fr-fic fr-fil fr-dib" width="585" style="width: 587px; height: 275.464px;" height="275"></p><p><strong><span style="font-size: 10pt;">Fig 8. Adding members to Group</span></strong></p><p><br></p><p>The Mapping Status of each member indicates when that member was last updated with the permissions/access of the Group. <img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdjNTM2NzgzLTEyNTMtNDgwZi1hMGE2LTdlOWQzN2ZmZWM5YyJ9.PEOLdXbjYZL92WGkg6ljByu6XtJLAKT_pRsV2jVY3fY" class="fr-fic fr-fil fr-dib" width="1736" style="width: 1738px; height: 361.95px;" height="362"></p><p><strong><span style="font-size: 10pt;">Fig 9. Members Added to Group</span></strong></p><p><br></p><p>Once added, the Groups an agent/user is in will be visible against their profile. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjM0ZjA4MmRiLWUzNDItNDRhNS1hNDM5LTRlNDE1ODRlZWY4MyJ9.rmv2dXwOyIhTMJ-y5miAAtLRsFtNd8F29nsxq5MlmpU" class="fr-fic fr-fil fr-dib" width="947" style="width: 949px; height: 428.28px;" height="428"></p><p><strong><span style="font-size: 10pt;">Fig 10. Groups an Agent is assigned to</span></strong></p><p><br></p><p><strong><em>Note: This will only show if the agent/user belongs to a Group. </em></strong></p><p><br></p><p><strong>Managing Members when the Group has been imported from Entra</strong></p><p>Groups imported from Entra will have members assigned automatically based on the members of the Group in Entra. Changes to Group members in Entra will be reflected in Halo each time the Entra integration sync runs. If an agent/user is added/removed from the Entra Group they will also be added/removed from the Halo group. </p><p><br></p><p>Keep in mind Entra can only manage members added by Entra and will ignore changes made manually. This means any members added to the Group manually will remain after an Entra sync even if they are not present in the Group in Entra. This prevents manual changes being overwritten by Entra. </p><p><br></p><p data-pasted="true"><strong><span style="font-size: 12pt;">Set the Roles/Teams Agents with this Group have (Agent Mappings)</span></strong></p><p>To set which roles and teams that the agents with this Group have, head to the "Agent Mappings" tab. </p><p><br></p><p>Add the roles and/or teams here you would like all the agents in this Group to have access to. When adding a team mapping you can configure the mapping to control the membership level agents in this Group are added to the team with. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjEzZjk4NzU1LTkzOTYtNDhkZS1hNzI3LTQyOGJlMjkwMzdhZSJ9.4f_V1V4QjKPjLisufEnIPf8GGFJI-dNelt8voMNmWNg" class="fr-fic fr-fil fr-dib" width="1747" style="width: 1749px; height: 672.938px;" height="673"></p><p><strong><span style="font-size: 10pt;">Fig 11. Agent Mappings</span></strong></p><p><br></p><p>If you have set a "Managed Team" this will show here automatically. </p><p><br></p><p>Agents will be assigned to teams here in addition to any team access granted via a role. </p><p><br></p><p data-pasted="true"><strong>User to Agent account mapping - </strong>Use this to ensure mappings are based on agent accounts rather than user accoun<span style="color: rgb(0, 0, 0);">ts. Only applicable when all Group members should be agents in Halo. When set any mapped users that do not have an agent account will have one created and linked to their user automatically. Should the user already be linked to an agent the mapping will be converted to an agent mapping rather than a user.</span></p><p><span style="color: rgb(0, 0, 0);"><br></span></p><p><span style="color: rgb(0, 0, 0);"><em><strong>Note: If any mapped users do not have a linked agent account but share the same name as an existing agent, a new agent will be created (linked to this user) with a unique name. </strong></em></span><strong><em><br></em></strong></p><p><br></p><p data-pasted="true"><strong><span style="font-size: 12pt;">Set the Roles Users with this Group will have (User Mappings)</span></strong></p><p data-pasted="true">To set which roles that the users with this Group have, head to the "User Mappings" tab. </p><p><br></p><p data-pasted="true">Add the roles here you would like all the users in this Group to have access to. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjgzOGQyNGRlLTQ5NDUtNDliYy04NTBiLTM1ZGZkMDg5NTMyOSJ9.FakufJoNsO27U8KZYwZm1cCFYvuepow0pxo3sOnYAd4" class="fr-fic fr-fil fr-dib" width="1736" style="width: 1738px; height: 354.726px;" height="355"></p><p><strong><span style="font-size: 10pt;">Fig 12. Add User Roles to Group</span></strong></p><p><br></p><p data-pasted="true"><strong><span style="font-size: 12pt;">Set the CABs Users and Agents with this Group will be in (CAB Mappings) </span></strong></p><p data-pasted="true">To set which CABs the users and agents with this role are in, head to the "CAB Mappings" tab. </p><p><br></p><p data-pasted="true">Add the CABs here you would like all the users and agents in this Group to have be in. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImRhNWNiOWE0LTEwOGYtNGMzMC1iZDdmLTM3ZGRkNTYxOGZjYyJ9.NL_Mf1I4SdfzGH7BtlvyaCvMiCYml3jUvmmidq-MLJY" class="fr-fic fr-fil fr-dib" width="1774" style="width: 1776px; height: 339.707px;" height="340"></p><p><strong><span style="font-size: 10pt;">Fig 13. Add CABs to Group </span></strong></p><p><br></p><p>When added to a CAB users and agents will be added to the CAB as a non mandatory approver. If a CAB is created from the Group using "Managed CAB", the CAB will default to requiring all members to approve. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6Ijc1YzU2NzBmLTVhNmUtNDJmMC1hMmM4LTEyYmI0MzE2ZTZmYiJ9.4OTFhtEcANrFfyzE9jL87HBLLaRozUfzPRe5pzemRRU" class="fr-fic fr-fil fr-dib" width="1783" style="width: 1785px; height: 551.55px;" height="552"></p><p><strong><span style="font-size: 10pt;">Fig 14. Approvers added to CAB from Group</span></strong></p><p><br></p><p><span style="font-size: 14pt;"><strong>Updating Mappings</strong></span></p><p data-pasted="true"><strong>Apply Mappings - </strong>Use this to force through the processing of any members that haven't had one or more mappings applied/removed yet. Each time a member or a mapping is updated mappings will be applied automatically, but this is used as a failsafe.</p><p><strong>Re-Process Mappings - </strong>Use this to re-check and re-apply every members mappings, regardless of whether they have been applied or not. Each time a member or a mapping is updated mappings will be applied automatically, but this is used as a failsafe.</p><p data-pasted="true"><br></p><p data-pasted="true"><strong><span style="font-size: 14pt;">Access Control</span></strong></p><p>Administrator agents will be able to create and edit all Groups. <a href="https://www.usehalo.com/guides/2426" target="_blank" rel="noopener noreferrer">Access Control</a> can be used to grant other agents access to view and or edit the Group configuration, useful for provisioning agents access to update the Group members, without requiring them to be a Halo admin. </p><p><br></p><p>To grant access control use the "Access Control" button against the Group. </p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjFkZmIzNGJhLTY0MmUtNDIyZS1hZjk3LTMzM2M2M2RkNTJjZCJ9.SnLE4zlcX3f-RSEGgnsTUW7BboLBOAB_MGcLSLfQjdk" width="858" style="width: 860px; height: 265.145px;" height="265" class="fr-fic fr-dii"></p><p><strong><span style="font-size: 10pt;">Fig 15. Access Control for Group</span></strong></p><p><br></p><p>When read and modify access is granted for the Group agents will be able to:</p><ul><li>View all the existing Group configuration, including members and team/role/CAB mappings</li><li>Add/remove Group members</li><li>Add/remove user role mappings</li><li>Apply Mappings</li><li>Re-process Mappings</li></ul><p><br></p><p>Agents with owner access will have the same access as those with read and modify, but will also be able to grant access control to other agents. </p><p><br></p><p>Once access control is granted agents will have the "Groups" module available in their "My Config" area. </p><p><br></p>