Create a directory-linked group
- In the management console, on the menu bar, click Groups > User.
- Click
.
- Type the group name.
- In the Linked directory groups section, do the following:
- Click
.
- Type the name or partial name of the company directory group that you want to link to.
- If you have more than one company directory connection, select the connection that you want to search. After you have made this selection, the directory-linked group is permanently associated with the selected connection.
- Click
.
- Select the company directory group.
- Click Add.
- If necessary, to allow the directory settings to control the number of nested groups, select the Link nested groups check box. To link to all nested groups, leave the check box unselected.
- Repeat these steps to link additional groups.
- Click
- Do any of the following:
Task
Steps
Assign a user role to the directory-linked group.
- In the User role section, click
.
- In the drop-down list, click the name of the user role that you want to assign to the group.
- Click Add.
Assign an IT policy or profile to the directory-linked group.
- In the IT policy and profiles section, click
.
- Click IT policy or a profile type.
- In the drop-down list, click the name of the IT policy or profile that you want to assign to the group.
- Click Assign.
- In the User role section, click
- If you want to assign an app or app group to the directory-linked group, do the following:
- In the Assigned apps section, click
.
- Search for and select the app or app group that you want to assign.
- Click Next.
- In the Disposition drop-down list, select one of the following:
- Required: Install the app automatically on devices and prevent users from uninstalling the app.
- Optional: Allow users to install and uninstall the app.
- Denied (Android only): Prevent users from installing the app.
- If you are assigning a Google Play app to Android Enterprise and Android Management devices, and you set the Disposition to required or optional, in the Update Mode drop-down list, click the appropriate option:
- Default: When a new version of the app is available in Google Play, the device is notified. Any restrictions or conditions from an assigned device SR requirements profile are applied to the app update.
- High Priority: When a new version of the app is available in Google Play, the device is notified. Any restrictions or conditions from an assigned device SR requirements profile are ignored. In larger deployments this can take up to 24 hours.
- Postpone: When a new version of the app is available in Google Play, the device is notified after 90 days, then the update is applied using latest available version. Any restrictions or conditions from an assigned device SR requirements profile are applied. Note that users can manually update the app at any time.
- If you are assigning an Apple VPP app, and you set the Disposition to required or optional, in the Update Mode drop-down list, click the appropriate option:
- Default: When a new version of the app is available, it will be pushed to devices automatically.
- Postpone: When a new version of the app is available, it will not be pushed to devices automatically.
- For iOS devices, to assign per-app VPN settings to an app or an app group, in the Per app VPN drop-down list, select the settings to associate with the app or app group.
- If you assign an iOS or OS X app, choose the appropriate value in the Target drop-down list:
- Work: The app is installed as a work app that you manage with UEM.
- Personal:
- If it is not a VPP app, the app is managed by UEM and a “personal” label is associated with the assigned app in the management console. The personal label does not impact how the app is managed on devices.
- If it is an iOS or OS X VPP app with the Disposition set to Optional, the user will be redirected to the App Store to install the app as unmanaged. Unmanaged apps cannot be removed from devices by UEM and are not subject to UEM controls such as IT policy rules. When you set the app assignment as Optional and Personal, you are prompted to assign the appropriate VPP user license to devices so it can be treated as an unmanaged app. You must set “Assign license to” to “User” to make it an unmanaged app.
- If available, for iOS and Android devices, in the App configuration drop-down list, click the app configuration that you want to assign to the app.
- If you use Android Enterprise and have created tracks for apps in the Google Play console, in the Track drop-down list, click the track to assign to the app.
- Click Assign.
- In the Assigned apps section, click
- Click Add.