For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security Groups

Security Groups define which users are allowed to access protected files. When a file is protected using GuardWare PROTECT, only users in the selected Security Groups can access it. Any user who is not a member of those groups is automatically restricted from accessing the file. Security Groups can be created manually or imported directly from Active Directory.

Users must be assigned to a Security Group to use GuardWare PROTECT on their PC. Any new user who installs GuardWare PROTECT Client and logs in successfully is automatically assigned to the default Security Group called All Users. A user can belong to multiple Security Groups.

Add a Security Group

  1. Log in to the GuardWare PROTECT Management Console.

  2. Go to PROTECT > Security Groups.

  3. Click +New Security Group. You’ll see an option to create a security group manually or from AD.

  4. To create manually:

    1. Select Manually.

    2. In Security Group Name, enter a descriptive name for the group that reflects its purpose.

    3. In Description, enter a summary of the group’s role or scope. This helps other administrators understand the intended use.

    4. In Encryption Mode, select how files can be decrypted:

      1. Online: Decryption is allowed only when the user is connected to the network.

      2. Offline: Decryption is allowed even when the user is not connected to the network.

    5. In Security Group Type, select how membership is managed:

      1. Private: Only members and administrators can see the group; it’s hidden from non-members.

      2. Public: Visible to all users, and anyone can see the group.

    6. Click Save.

  5. To import from AD:

    1. Select From the AD.

    2. Search for the required AD group. Matching Security Groups appears in the SECURITY GROUPS list.

    3. Select the AD group. The selected group appears in the Selected Security Group panel on the right.

    4. Click Save. The group will now appear in the Security Group List. You can view the list either by the Group name or by users.

Assign Users to Security Group

  1. Go to PROTECT > Security Groups.

  2. Search for the security group to assign users and click +Assign Users in the ACTIONS column. You’ll see the list of all users, including AD and external users.

External users appear on the list only after they have accepted the invitation, installed GuardWare PROTECT, and logged in successfully. For details on how to invite external users, see Invite External Users.

  1. Search and select the users to add, and click Assign Users.

Assign Security Groups to Users

  1. Go to PROTECT > Security Groups.

  2. Click Users.

External users appear on the list only after they have accepted the invitation and installed GuardWare PROTECT. For details on how to invite external users, see Invite External Users.

  1. Search for the user and click Assign Security Group in the ACTIONS column. You’ll see the list of all Security Groups.

  2. Select the Security Groups and click Assign Security Group.

From here, you can also perform the following actions:

  1. Enable/Disable User

  2. Enable/Disable Log

  3. Encrypt Files

  4. Decrypt Files

Edit a Security Group

  1. Go to PROTECT > Security Groups and search for the security group to edit.

  2. In the ACTIONS column, click the Edit icon.

  3. Update the required details and click Save.

Disable a Security Group

Disabling a security group immediately removes all assigned users from the group and revokes any permissions granted through it. The group remains available for future use, but you cannot add users while it is disabled. If you re-enable the group, you must add the users again.

Disabling a security group is useful when access needs to be revoked quickly. For example, when a project is completed, and all related files should no longer be accessible, disabling the project’s security group instantly removes access for all members.

To disable a Security Group:

  1. Go to PROTECT > Security Groups and search for the security group you want to disable.

  2. In the ACTIONS column, click Disable.

  3. Click Confirm.

The All Users default group cannot be disabled.

Last updated