User and group access entitlements
The permissions to manage users and groups are split into separate user and group entitlements. When you view or edit a group in the UI to search for the members, the following group entitlements cannot access group members on their own. They require an extra user entitlement.
readGroupMembersandmanageGroupMembersrequirereadUsersGroupMembershipor an entitlement with higher-level access such asmanageUsers, which also impliesreadUsersGroupMembership.readStandardGroupMembersandmanageStandardGroupMembersrequirereadUsersStandardGroupMembershipor an entitlement with higher-level access such asmanageUsersInStandardGroups, which also impliesreadUsersStandardGroupMembership.updateAnyGroupMemberrequiresreadStandardGroupMembers, orreadGroupMembers, or an entitlement with higher-level access for group members access. It also requiresreadUsersGroupMembershipor an entitlement with higher-level access such asmanageUsers, which impliesreadUsersGroupMembership, for users and group membership access.
Extra permission requirements for functions
- Advanced Search requires
readAttributes. To take fuller advantage of the advanced search function, addreadIdentitySources. - User information requires
readAttributes. - Add user requires
readIdentitySourcesandreadAttributes. - Edit user requires
readAttributes. - Edit security settings requires
readPwdPolicy.
Additions permission requirements for group functions
- Edit assigned password policy requires
readPwdPolicy.
For a list of entitlements, see Access entitlements.