Create a security group
Where a client runs their own directory, the group is created there rather than in the cloud. Avvi routes it and refuses if it cannot reach them.
A security group controls access rather than mail. Creating one takes a name and, optionally, owners and members.
Where the group is created depends on whether a connector for that client’s directory is enrolled. Where one is, and it is reachable, the group is created in their directory so it syncs upward like every other group they have.
Where a connector is enrolled and unreachable, Avvi refuses rather than creating a cloud group that would sit alongside the real ones.
Where no connector is enrolled at all, Avvi has no way to know the client runs a directory, and creates the group in the cloud.
Before you begin
Check whether a connector for that client is enrolled and reachable. That, rather than whether they own a directory, is what decides where the group lands.
Have the name settled. Renaming a group afterwards is possible and is more disruptive than getting it right.
Decide on owners and members, or add them afterwards.
Create it
- Open chat and check the client.
- Say what you want, naming the group. For example: create a security group called Finance Approvers.
- Answer where it should be created, if Avvi asks. On a client with a connector it may offer the choice.
- Read the confirmation, checking the name, then confirm.
A group created in the client’s directory is reported as an Active Directory group. A cloud group is reported without naming a location, so no mention of Active Directory means the cloud.
Good to know
A security group is not a distribution list and not a Microsoft Team. It grants access rather than delivering mail.
Where a client has their own directory, groups created there appear in the cloud after their own synchronisation runs rather than instantly.
Verify it worked
Ask Avvi for the group and confirm the name and the members.
On a client with their own directory, allow time for their synchronisation before expecting to see it in the cloud.
If something doesn’t look right
If Avvi refuses and names the connector, the client’s directory is not reachable. Bring the connector back and ask again.
If the group appears in the cloud on a client who runs their own directory, no connector was enrolled for it. Decide whether that is what you wanted before adding anybody to it.
If the group does not appear after creation on a hybrid client, wait for their synchronisation cycle before treating it as a failure.
To report a failure, open a support conversation from the Help drawer with the client and the group name.
FAQ
Q: Where is the group created?
A: In the client’s directory when a connector for it is enrolled and reachable. Refused when a connector is enrolled and unreachable. In the cloud when none is enrolled.
Q: Why did Avvi refuse?
A: Because the client’s directory was unreachable and a cloud group would have been the wrong answer.
Q: Is this the same as a distribution list?
A: No. A security group controls access; a distribution list delivers mail.