> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/protect/users-and-devices/security-groups.md).

# Security Groups

Security Groups define which users are allowed to access protected files. When a file is protected using GuardWare PROTECT, only users in the selected Security Groups can access it. Any user who is *not* a member of those groups is automatically restricted from accessing the file. Security Groups can be created manually or imported directly from Active Directory.

Users must be assigned to a Security Group to use GuardWare PROTECT on their PC. Any new user who installs GuardWare PROTECT Client and logs in successfully is automatically assigned to the default Security Group called *All Users*. A user can belong to multiple Security Groups.

### Add a Security Group

1. Log in to the GuardWare PROTECT Management Console.
2. Go to **PROTECT > Security Groups**.
3. Click **+New Security Group**. You’ll see an option to create a security group manually or from AD. &#x20;

   <figure><img src="/files/6InOe8oYin95pGx0SSGZ" alt=""><figcaption></figcaption></figure>
4. To create manually:
   1. Select **Manually**.\
      &#x20;

      <figure><img src="/files/92d6e7b02514dbfef86f74414671597e87f92d05" alt=""><figcaption></figcaption></figure>
   2. In **Security Group Name**, enter a descriptive name for the group that reflects its purpose.
   3. In **Description**, enter a summary of the group’s role or scope. This helps other administrators understand the intended use.
   4. In **Encryption Mode**, select how files can be decrypted:
      1. **Online**: Decryption is allowed only when the user is connected to the network.&#x20;
      2. **Offline:** Decryption is allowed even when the user is not connected to the network.
   5. In **Security Group Type,** select how membership is managed:
      1. **Private:** Only members and administrators can see the group; it’s hidden from non-members.
      2. **Public:** Visible to all users, and anyone can see the group.
   6. Click **Save**.
5. To import from AD:
   1. Select **From the AD**.
   2. Search for the required AD group. Matching Security Groups appears in the **SECURITY GROUPS** list.
   3. Select the AD group. The selected group appears in the **Selected Security Group** panel on the right.
   4. Click **Save**.\
      The group will now appear in the **Security Group List**. You can view the list either by the Group name or by users.

### Assign Users to Security Group

1. Go to **PROTECT > Security Groups**.
2. Search for the security group to assign users and click **+Assign Users** in the **ACTIONS** column. You’ll see the list of all users, including AD and external users.\
   &#x20;

   <figure><img src="/files/6hSAEYMmqztZTo9yVyld" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
External users appear on the list only after they have accepted the invitation, installed GuardWare PROTECT, and logged in successfully. For details on how to invite external users, see [Invite External Users](/protect/users-and-devices/invite-external-users.md).
{% endhint %}

3. Search and select the users to add, and click **Assign Users**.

![](/files/7360c31ff286bd8d010b46c8a1c2e440d2aca307)

### Assign Security Groups to Users

1. Go to **PROTECT > Security Groups**.
2. Click **Users**.\
   &#x20;

   <figure><img src="/files/tnwi8JiWL0n5b60j7uVA" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
External users appear on the list only after they have accepted the invitation and installed GuardWare PROTECT. For details on how to invite external users, see [Invite External Users](/protect/users-and-devices/invite-external-users.md).
{% endhint %}

3. Search for the user and click **Assign Security Group** in the **ACTIONS** column. You’ll see the list of all Security Groups.<br>

   <figure><img src="/files/3vFLIN5kikVagJ9M7qhb" alt=""><figcaption></figcaption></figure>
4. Select the Security Groups and click **Assign Security Group**.

From here, you can also perform the following actions:

1. [Enable/Disable User](https://docs.guardware.com/protect/users-and-devices/pages/MBylhwBiBz1LYjFFWcal#id-1.-enable-disable-user)
2. [Enable/Disable Log](https://docs.guardware.com/protect/users-and-devices/pages/MBylhwBiBz1LYjFFWcal#id-2.-enable-disable-log)
3. [Enable/Disable Force Encrypt](https://docs.guardware.com/protect/users-and-devices/pages/MBylhwBiBz1LYjFFWcal#id-3.-enable-disable-force-encrypt)
4. [Encrypt Files](https://docs.guardware.com/protect/users-and-devices/pages/MBylhwBiBz1LYjFFWcal#id-4.-encrypt-files)
5. [Decrypt Files](https://docs.guardware.com/protect/users-and-devices/pages/MBylhwBiBz1LYjFFWcal#id-5.-decrypt-files)

### Edit a Security Group

1. Go to **PROTECT > Security Groups** and search for the security group to edit.
2. In the **ACTIONS** column, click the **Edit** icon. <br>

   <figure><img src="/files/qAff40Q22MhoownCIn0z" alt=""><figcaption></figcaption></figure>
3. Update the required details and click **Save**.

### Disable a Security Group

Disabling a security group immediately removes all assigned users from the group and revokes any permissions granted through it. The group remains available for future use, but you cannot add users while it is disabled. If you re-enable the group, you must add the users again.

Disabling a security group is useful when access needs to be revoked quickly. For example, when a project is completed, and all related files should no longer be accessible, disabling the project’s security group instantly removes access for all members.

To disable a Security Group:

1. Go to **PROTECT > Security Groups** and search for the security group you want to disable.
2. In the **ACTIONS** column, click **Disable**. <br>

   <figure><img src="/files/ivkI9wJa1plJeXIjJ8BS" alt=""><figcaption></figcaption></figure>
3. Click **Confirm**.

{% hint style="info" %}
The **All Users** default group cannot be disabled.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/protect/users-and-devices/security-groups.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
