πŸŽ“ Group Settings

Manage group configurations, user permissions, and security settings.

Note:
Security principles for user and rights management
We strongly recommend adhering to proven security principles when using our platform. These include in particular:

  • Segregation of Duties: Roles and responsibilities should be distributed so that no single person has complete control over security-relevant processes. This reduces the risk of misuse and unintentional errors.
  • Principle of Least Privilege: Users should only receive the access rights they strictly need to perform their tasks. Excessive permissions increase the attack surface and the risk of data leaks.
  • Principle of Need to Know: Access to sensitive information should be restricted to those who need this information for their specific work. This effectively strengthens the protection of confidential data.

 

The consistent implementation of these principles contributes significantly to securing your environment and meeting common compliance requirements.

Every user is assigned to a group when created, which contains the corresponding permissions and licenses.

In the group configuration, the rights and licenses of the corresponding users can be defined. In addition, security settings, automatic deletion periods, and cleanups can also be stored for the group.

In the navigation, the group settings can be found under the "Administration" tab, then select the "Groups" option on the left under "Configuration".

Basic Details & Members

In the "Basic Details" area, the name of the group can be edited and a description for the group can be added.

Under "Members", you can see which users are in this group and users can be added manually to the group by entering their email address or username.

Features

In the Features area, it is determined which products and features are enabled for the group and its users.

A distinction is made between license-free and license-required features.

Note: If license-required features are assigned to the group, a license will be due for every user added to the group.

Restrictions

In the "Restrictions" area, specific restrictions can be set for each group:

Max. attachment size for WebUpload: Maximum total size of all files that can be sent as a delivery via the FTAPI web interface.

Maximum segment size of the upload: Maximum size of segments.

Whitelist for delivery recipients: Members of this group may only send deliveries to the recipients and domains stored here. Add domains to the whitelist: *@company.com.

Blacklist for delivery recipients: Members of this group may not send deliveries to the recipients and domains stored here.

IP address restriction: Allowed IP address range for users of this group.

Blacklist for file types: Users may not send the file types stored here as a delivery and they will not be accepted for SecuForms and SubmitBox submissions or SecuRooms uploads.

FTAPI Blacklist example:

*.ace,.ade,*.adp,*.apk,*.appx,*.appxbundle,*.arj,*.bat,*.bz2,*.cab,*.chm,
*.cmd,*.com,*.cpio,*.cpl,*.diagcab,*.diagcfg,*.diagpack,*.dll,*.dmg,*.doc,
*.docm,*.ex,*.ex_,*.exe,*.flv,*.hta,*.img,*.ins,*.io,*.iso,*.isp,*.jar,
*.jnlp,*.js,*.jse,*.jsxbin,*.lha,*.lib,*.lnk,*.lzh,*.lzma,*.mde,*.mht,
*.msc,*.msi,*.msix,*.msixbundle,*.mslz,*.msp,*.mst,*.nsh,*.one,*.onepkg,
*.onetoc2,*.pif,*.ppt,*.pptm,*.ps1,*.rtf,*.scr,*.sct,*.shb,*.smzip,*.swf,
*.sys,*.tar,*.udf,*.vb,*.vbe,*.vbs,*.vhd,*.vmdk,*.vxd,*.wsc,*.wim,*.wsf,
*.wsh,*.xll,*.xlm,*.xls,*.xlsm,*.xz,*.z

Maximum storage: Max. storage quota per member of this group.

Address book:   If enabled, possible recipients (= users registered in the system) are suggested to the users of the group.                 

Restriction of user administration access:  Only relevant for groups where the "User Administration" feature is enabled. Restricts administration to the selected user groups.

Change email address: If enabled, users of this group can change their email address.

Delete deliveries in inbox/outbox:
If enabled, users of this group can delete deliveries.

Cleanup

In this area, automated cleanups (= cleanup jobs) can be set.

  1. User account cleanup:
    If enabled, the user account is deactivated or deleted after X days. Furthermore, it can be set whether users receive a notification about deactivation/deletion in advance.
  2. Storage, delivery, and data room upload cleanup:
    If enabled, the delivery is deleted after a defined period X. Furthermore, it can be set that users can individually configure the validity period per delivery.

 

To set up automated cleanup for individual groups, cleanup must first be enabled in the system settings. To the article.

Security Level

In this area, you can define which security levels for SecuMails, the SubmitBox, and SecuRooms the members of a group can use.

  1. SecuMails:
    Enabled security levels are available for selection when sending deliveries. You can also set a default security level: This will be automatically preselected in the web interface and can be adjusted by the user if necessary.
  2. SubmitBox:
    Enabled security levels are permitted for receiving submissions.
  3. SecuRooms:
    Enabled security levels determine which types of data rooms may be created (unencrypted, encrypted, both).

Two-Factor Authentication

In this area, the security add-on Two-Factor Authentication can be managed.

  • Two-Factor Authentication via SMS:
    If enabled, users of this group must verify themselves via a second factor when logging in. The second factor is a one-time code that the user receives via SMS and enters in the login mask for authentication.
  • Two-Factor Authentication via App:
    If enabled, users of this group must verify themselves via a second factor when logging in. The second factor is a one-time code that the user retrieves via an authentication app and enters in the login mask for authentication.

 

Account Verification 

In this area, the security add-on account verification via email can be managed. 

  • Account verification via email:
    If enabled, users must verify themselves when logging in by entering a security code that is sent to the email address of the user account.

Note: The add-on is located under Two-Factor Authentication. More details.

Double-authenticated registration

In this area, the security add-on Double-authenticated registration can be managed.

  • Double-authenticated registration:
    If enabled, users of this group must verify themselves via a second factor during self-registration in the system. The second factor is a one-time code that the user receives via SMS and enters for authentication.

"Group Settings" section completed!

Congratulations, the "Group Settings" section has been successfully completed!

 

< Previous chapter      To the overview      Next chapter >