Group Rules

Add a Group Rule

To add a group rule:

1. On the Privileged Access Group Rules page, click Add Group Rule.

2. In the Add Group Rule panel that opens, select the Target. For device-specific rules, follow the steps in Target a Group Rule at a Single Device.

3. Select the Local Group, or add one, in the drop-down menu. 

4. Select the Member (Administrator, Temporary Administrator, Local Administrator), or add a local user, in the drop-down menu.

5. Enable Set validity end time, if desired. Enter or select the expiry time.

6. Confirm that the Rule is active.

7. Click Save.

For group rules where the Member is an Entra ID group

To ensure that administrator rights are assigned correctly, Microsoft recommends a limit of 20 Microsoft Entra groups on each device, and that each user's memberships be limited to 20 groups. The limitation also applies to nested groups.





Target a Group Rule at a Single Device

You can target group rules at an individual device without first needing to create a target group.

When you choose a single device as the target, Privileged Access automatically creates a target group with the device name and links the group to the rule.

To target a group rule to a single device:

1. Navigate to Privileged Access > ConfigurationGroup Rules and click Add Group Rule.

2. In the Add Group Rule panel that opens, target the rule to a single device.

3. Select a Recast Agent or search for the device from the domain.

If there isn't already a target group with that device name, Privileged Access will automatically create a target group with the device's name, add the device to that target group, and target the rule to that target group.

4. Enable Set validity end time, if desired. Enter or select the expiry time.

5. Confirm that the Rule is active.

6. Click Save.





Edit a Group Rule

To edit a group rule:

1. On the Group Rules page, click the Edit icon to the left of a group rule.

2. In the side panel that opens, edit the Local Group, the Member (Administrator, Temporary Administrator, Local Administrator), the Validity End Time and whether the rule is active.

3. Click Save.




Delete a Group Rule

To delete a group rule:

On the Privileged Access Group Rules page, click the Delete icon to the left of a group rule and confirm the deletion.