Learn how to create a Cloud Dynamic User Group in the Cloud Identity Engine.
| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
Cloud Dynamic User Groups simplify the creation of group-based Security policy by
providing adaptable and granular group membership that updates automatically based
on the criteria (also known as context or attributes) you specify. This allows you
to create a policy that adapts to changes in user behavior, location, and other
conditions where context plays a key role in determining access.
As work locations change and users take on different roles in an organization,
determining user privileges based on attributes such as department or location is no
longer sufficient. Cloud Dynamic User Groups provide a simplified and automated
solution by allowing you to specify the context for group membership based on
attributes that can change (such as location, department, or title), allowing you to
create more responsive group-based policy.
You can also create static groups where membership remains constant until you
manually add or remove members. For example, you can use static groups to quickly
assign privileges or to isolate an account that’s exhibiting unusual or risky
behavior based on specific events.
If you're using
Microsoft Active Directory Identity
Protection, you can use the risk assessment information to create Cloud
Dynamic User Groups based on a user's risk level or anomalous user behavior, such as
an unusual login location.
Using risk assessment information to create Cloud Dynamic
User Groups requires the
client credential flow for Azure
AD. You must
allow the following permissions in the Azure Portal to enable support for risk-based
attributes:
- IdentityRiskyUser.Read.All
- IdentityRiskEvent.Read.All