Specifying additional attributes that can be used to create dynamic user groups

Important: IBM Cloud Pak for Data Version 4.7 will reach end of support (EOS) on 31 July, 2025. For more information, see the Discontinuance of service announcement for IBM Cloud Pak for Data Version 4.X.

Upgrade to IBM Software Hub Version 5.1 before IBM Cloud Pak for Data Version 4.7 reaches end of support. For more information, see Upgrading IBM Software Hub in the IBM Software Hub Version 5.1 documentation.

In a dynamic user group, attribute-based rules determine which users are included in the group. By default, you can use a limited set of attributes to create dynamic user groups. However, you might want to use additional attributes when you create the groups.

Before you begin

Cloud Pak for Data must be configured to use the IBM Cloud Pak foundational services Identity Management Service. For more information, see Integrating with the Identity Management Service.

About this task

By default, you can use only the following attributes from your identity provider (IdP) to define a dynamic user group:
  • Location
  • Nationality
  • Organization
  • User type
However, you might want to use additional attributes when you create a user group. For example, you might want to:
  • Prevent users from accessing a catalog unless they pass a specific training course on handling personally identifiable information.
  • Allow users who are involved in a particular initiative to access the project that is associated with the initiative.

Cloud Pak for Data supports the following methods for specifying additional attributes:

Option Use this option if...
Using additional attributes from your IdP (recommended) The attributes that you want to use exist in your IdP.
Using a custom attributes provider The attributes that you want to use do not exist in your IdP

Both methods append the specified attributes to a user's Cloud Pak for Data user profile.

Procedure

Use the appropriate method to specify additional attributes that can be used to create dynamic user groups: