All Products
Search
Document Center

Secure Access Service Edge:user group management

Last Updated:Mar 31, 2026

User groups define which users a zero trust policy applies to. Each group selects users by account name, email address, mobile phone number, or organizational structure. When you create a policy, you assign one or more user groups to set its scope.

Prerequisites

Before you begin, ensure that you have:

Create a user group

  1. Log on to the Secure Access Service Edge console.

  2. In the left navigation pane, choose Identity Authentication > Identity Access.

  3. On the User Group Management tab, click Create User Group.

  4. In the Create User Group panel, configure the following parameters.

    image

    ParameterDescription
    User Group NameA name for the user group.
    DescriptionA description of the user group.
    Group ScopeHow users are selected for the group. Valid values: Organizational Structure, Account Name, Email Address, Mobile Phone Number. If you select Organizational Structure, the organizational structures from your configured and enabled identity sources are displayed for selection. If you select Account Name, the Configure Account Name field appears. If you select Email Address, the Configure Email Address field appears. If you select Mobile Phone Number, the Configure Mobile Phone Number field appears.
    Configure RelationshipThe relationship for the user group. Valid values: Equal To, Not Equal To.
  5. Click OK.

The new user group is automatically added to the user group list.

Manage user groups

On the User Group Management tab, you can also:

  • Edit: Click Edit to view or modify the user group configuration.

  • Delete: Click Delete to remove the user group.

What's next

After you create a user group, assign it to a zero trust policy to define which users the policy covers. For details, see Configure a zero trust policy for private access.