{"id":119,"date":"2016-02-19T10:58:29","date_gmt":"2016-02-19T10:58:29","guid":{"rendered":"https:\/\/blogs.ncl.ac.uk\/integration\/?p=119"},"modified":"2016-02-24T14:10:41","modified_gmt":"2016-02-24T14:10:41","slug":"make-applications-groups-specific","status":"publish","type":"post","link":"https:\/\/blogs.ncl.ac.uk\/integration\/2016\/02\/19\/make-applications-groups-specific\/","title":{"rendered":"Make &#8216;Applications&#8217; groups specific"},"content":{"rendered":"<p>Our sixth\u00a0<a href=\"https:\/\/blogs.ncl.ac.uk\/integration\/2016\/02\/19\/principles-tips-and-good-practice-for-grouper-administrators-at-newcastle-university\/\">principle of Grouper good practice<\/a> is:<\/p>\n<ul>\n<li><strong>Make &#8216;Applications&#8217; groups specific <\/strong>to a service or purpose.<\/li>\n<\/ul>\n<p>This should ensure that <a href=\"https:\/\/blogs.ncl.ac.uk\/integration\/2016\/02\/19\/adhere-to-the-naming-convention-for-applications-groups\/\">each group provisioned to AD has a clear purpose<\/a>\u00a0and avoid any unforeseen consequences when a group is deleted, for example.<\/p>\n<p>Additionally, requirements can change. Initially you might want to control access to a number of services with the same group but, over time, the people you want to grant access to might diverge from the original group. This scenario is best served by having specific &#8216;Applications&#8217; groups all <a href=\"https:\/\/blogs.ncl.ac.uk\/integration\/2016\/02\/19\/create-a-user-group-if-youre-likely-to-reuse-the-same-set-of-members\/\">containing the same &#8216;User Groups&#8217; group as a member<\/a>. This gives the flexibility to allow the memberships to diverge, if required.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our sixth\u00a0principle of Grouper good practice is: Make &#8216;Applications&#8217; groups specific to a service or purpose. This should ensure that each group provisioned to AD has a clear purpose\u00a0and avoid any unforeseen consequences when a group is deleted, for example. &hellip; <a href=\"https:\/\/blogs.ncl.ac.uk\/integration\/2016\/02\/19\/make-applications-groups-specific\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1062,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[13,12,4],"class_list":["post-119","post","type-post","status-publish","format-standard","hentry","category-group-management","tag-admin","tag-principles","tag-tips"],"_links":{"self":[{"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/posts\/119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/users\/1062"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/comments?post=119"}],"version-history":[{"count":5,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/posts\/119\/revisions"}],"predecessor-version":[{"id":129,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/posts\/119\/revisions\/129"}],"wp:attachment":[{"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/media?parent=119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/categories?post=119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/integration\/wp-json\/wp\/v2\/tags?post=119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}