Chapter 27. Managing user groups in IdM Web UI


Manage user groups in Identity Management (IdM) using the Web UI to organize users with common privileges, password policies, and other characteristics. User groups simplify administration by applying policies to multiple users at once.

A user group is a set of users with common privileges, password policies, and other characteristics.

A user group in IdM can include:

  • IdM users
  • other IdM user groups
  • external users, which are users that exist outside of IdM

27.1. Different group types in IdM

Identity Management (IdM) supports three types of user groups—POSIX, non-POSIX, and external—each suited to different identity store integrations and Linux attribute requirements.

POSIX groups (the default)

POSIX groups support Linux POSIX attributes for their members. Note that groups that interact with Active Directory cannot use POSIX attributes.

POSIX attributes identify users as separate entities. Examples of POSIX attributes relevant to users include uidNumber, a user number (UID), and gidNumber, a group number (GID).

Non-POSIX groups

Non-POSIX groups do not support POSIX attributes. For example, these groups do not have a GID defined.

All members of this type of group must belong to the IdM domain.

External groups

Use external groups to add group members that exist in an identity store outside of the IdM domain, such as:

  • A local system
  • An Active Directory domain
  • A directory service

External groups do not support POSIX attributes. For example, these groups do not have a GID defined.

Expand
Table 27.1. User groups created by default
Group nameDefault group members

ipausers

All IdM users

admins

Users with administrative privileges, including the default admin user

editors

This is a legacy group that no longer has any special privileges

trust admins

Users with privileges to manage the Active Directory trusts

When you add a user to a user group, the user gains the privileges and policies associated with the group. For example, to grant administrative privileges to a user, add the user to the admins group.

Warning

Do not delete the admins group. As admins is a pre-defined group required by IdM, this operation causes problems with certain commands.

In addition, IdM creates user private groups by default whenever a new user is created in IdM. For more information about private groups, see Adding users without a private group.

27.2. Direct and indirect group members

You can manage group membership inheritance in Identity Management (IdM) by using direct and indirect members. Nested group structures simplify policy administration by automatically applying group attributes to all member levels.

User group attributes in IdM apply to both direct and indirect members: when group B is a member of group A, all users in group B are considered indirect members of group A.

For example, in the following diagram:

  • User 1 and User 2 are direct members of group A.
  • User 3, User 4, and User 5 are indirect members of group A.

Figure 27.1. Direct and Indirect Group Membership

A chart with Group A (with 2 users) and Group B (with 3 users). Group B is nested inside Group A so Group A contains a total of 5 users.

If you set a password policy for user group A, the policy also applies to all users in user group B.

27.3. Adding a user group using IdM Web UI

Create user groups in the Identity Management (IdM) Web UI to organize users and manage access control policies collectively. Groups simplify administration by allowing you to assign permissions and roles to multiple users at once.

Prerequisites

  • You are logged in to the IdM Web UI.

Procedure

  1. Click Identity Groups, and select User Groups in the left sidebar.
  2. Click Add to start adding the group.
  3. Fill out the information about the group. For more information about user group types, see Different group types in IdM.

    You can specify a custom GID for the group. If you do this, be careful to avoid ID conflicts. If you do not specify a custom GID, IdM automatically assigns a GID from the available ID range.

  4. Click Add to confirm.

27.4. Deleting a user group using IdM Web UI

You can delete user groups using the Identity Management (IdM) WebUI. Deleting a group does not delete the group members from IdM.

Prerequisites

  • You are logged in to the IdM Web UI.

Procedure

  1. Click Identity Groups and select User Groups.
  2. Select the group to delete.
  3. Click Delete.
  4. Click Delete to confirm.

Add users and user groups as members of a user group in the Identity Management (IdM) Web UI to organize permissions and access control efficiently. Group membership simplifies user management by applying policies to multiple users simultaneously.

Prerequisites

  • You are logged in to the IdM Web UI.

Procedure

  1. Click Identity Groups and select User Groups in the left sidebar.
  2. Click the name of the group.
  3. Select the type of group member you want to add: Users, User Groups, or External.
  4. Click Add.
  5. Select the checkbox next to one or more members you want to add.
  6. Click the right arrow to move the selected members to the group.
  7. Click Add to confirm.

Designate users or user groups as member managers using the Identity Management (IdM) Web UI to delegate user group membership management. Member managers can add or remove group members without having full administrative privileges.

Prerequisites

  • You are logged in to the IdM Web UI.
  • You must have the name of the user or group you are adding as member managers and the name of the group you want them to manage.

Procedure

  1. Click Identity Groups and select User Groups in the left sidebar.
  2. Click the name of the group.
  3. Select the type of group member manager you want to add: Users or User Groups.
  4. Click Add.
  5. Select the checkbox next to one or more members you want to add.
  6. Click the right arrow to move the selected members to the group.
  7. Click Add to confirm.

    Note

    After you add a member manager to a user group, the update may take some time to spread to all clients in your Identity Management environment.

Verification

  • Verify the newly added user or user group has been added to the member manager list of users or user groups:

    idm groups member manager added

27.7. Viewing group members using IdM Web UI

View both direct and indirect members of an Identity Management (IdM) user group in the IdM Web UI to understand group membership inheritance across nested groups.

Prerequisites

  • You are logged in to the IdM Web UI.

Procedure

  1. Select Identity Groups.
  2. Select User Groups in the left sidebar.
  3. Click the name of the group you want to view.
  4. Switch between Direct Membership and Indirect Membership.

Additional resources

Remove users, nested groups, or external members from an Identity Management (IdM) user group in the IdM Web UI to revoke their inherited group privileges.

Prerequisites

  • You are logged in to the IdM Web UI.

Procedure

  1. Click Identity Groups and select User Groups in the left sidebar.
  2. Click the name of the group.
  3. Select the type of group member you want to remove: Users, User Groups, or External.
  4. Select the checkbox next to the member you want to remove.
  5. Click Delete.
  6. Click Delete to confirm.

Remove users or groups as member managers from an Identity Management (IdM) user group by using the IdM Web UI to revoke their ability to manage group membership. Member managers can add and remove group members but cannot change the group’s attributes.

Prerequisites

  • You are logged in to the IdM Web UI.
  • You must have the name of the existing member manager user or group you are removing and the name of the group they are managing.

Procedure

  1. Click Identity Groups and select User Groups in the left sidebar.
  2. Click the name of the group.
  3. Select the type of member manager you want to remove: Users or User Groups.
  4. Select the checkbox next to the member manager you want to remove.
  5. Click Delete.
  6. Click Delete to confirm.

    Note

    After you remove a member manager from a user group, the update may take some time to spread to all clients in your Identity Management environment.

Verification

  • Verify the user or user group has been removed from the member manager list of users or user groups:

    idm groups member manager removed
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat Documentation

Legal Notice

Theme

© 2026 Red Hat
Back to top