Properties of a Person Group Login
The login of a person group is created automatically on creation of the person group.
To:
User code
The User Code is the short identifier (upper case, maximum length 6 characters) of the person group.
This code is defined automatically on creation of the person group.
E.g.: SUPPOR
Login Holder
The login holder is the person group associated with the login.
E.g.: Support France
Repository access definition mode
Repository access of a person group is defined by the following access modes:
• Implicit access:
By default, the person group has read/write access to all repositories, but access can be limited or prohibited.
• Explicit access:
By default, the person group cannot access repositories, but access can be authorized. In this case, you must at least define and authorize access to a repository.

This mode is useful to install a confidentiality policy; it is preferable to first create a person group with explicit repository access, then progressively define its rights and the information it can access.
At creation of a person group, default access to repositories is as defined in environment and site options (Options/Repository) via the Repository default access mode option.
Repository access rights of the person group
At creation, a person group can access all repositories by default.
Person group
access rights to environment repositories can be restricted by the administrator. He can:
• authorize repository update (Read/Write)
• prohibit repository update (Read-only)
• prohibit repository access (Not accessible)
If the person group already has repository access rights restricted by those defined on his/her profile, only the restricted access rights will be defined on the profile.
Inactive person group (Status)
Login status can be used to make a person group inactive (value: Inactive). Users belonging to the person group can no longer have access to repositories through the person group, but trace of their actions are retained. The person group can be easily reactivated (value: Active).

When you delete a person group from the repository, the commands connected to the users belonging to the person group are kept as long as the users are not deleted.
Products accessible on the license (Command Line)
The Command Line field enables restriction of access of a user or profile to available products.
If a user is connected to a profile and the user and profile each have access to products restricted by the
Command Line attribute, the products accessible to the user are at the intersection of the values of the
Command Line attribute of the user and profile.
Authentication mode
Default value of the Authentication Mode parameter on the user login is inherited at user creation from the Authentication Mode option defined in the options of the environment (Options/Installation/User Management).
Authentication mode of a user is by checking the user password. Available authentication modes are:
• MEGA
Passwords are managed and stored in the MEGA repository.
This is default authentication mode.
• Windows
Passwords are managed and stored in Windows. This allows the user connected to Windows to be recognized automatically when he/she is connected to MEGA (Windows Front-End), not requiring entry of his/her password.
Attention: to connect to a
MEGA (Web Front-End) application, the user must enter his/her password.
The list of users in your MEGA environment is automatically synchronized with the list of users defined in your Windows network.
• LDAP
Passwords are managed and stored in the LDAP server of the enterprise. The directory configuration is stored in options.
The MEGA user is authenticated at LDAP server level.
• Custom
This authentication is managed by an external authentication module or SSO. This authentication mode is specific to Web connection to Web applications.

See the technical article
Web connection overloading and configuration EN .
Windows identifier
To connect to a MEGA application (Web Front-End), the user must enter his/her password.
LDAP server
The LDAP Server is the server with which the MEGA user is authenticated in LDAP authentication mode.
This server contains the LDAP directory in which the MEGA user is registered.
Profile

To be able to connect to
MEGA the user must have at least one profile.
By default, no profile is assigned to the login of a user or user group, you must connect at least one profile to the login.
The profile determines:
• access to objects and tools
• connection to Web applications
• repository access
• access to products

If a user already has access rights restricted by the
Command Line attribute on his/her
Login (see
"Viewing Login Characteristics"), the products accessible to this user are at the intersection of values of the
Command Line attribute of the user login and profile.
At installation, some profiles are already available in the environment.
Administrator profile
This attribute enables connection of an administrator profile to a user so that this user can connect to the Administration application (Windows Front-End).