Staff and Student Group Memberships in IDM Supervault

Question

What is the primary purpose and access provided by the Staff and Student groups in SuperVault?

 

Environment

  • Supervault

 

Information

Staff Group Membership

The Staff group (Staff.replicated.group.data) is a user security group used to flag individuals as staff members within SuperVault. This flag is replicated to both active directory domains (ad.grcc.edu and in.grcc.edu). Currently, the staff group is manually set, but it will eventually be replaced by the automated ActiveStaff group.

Permissions and access control

Staff group members have access to various systems and applications, which include but are not limited to:

  • Atrium Core SSO Login: Security control requiring an account in the system.

  • Barnes Noble College SSO Login: Security control requiring an account in the system.

  • Canvas Beta SSO Login: Security control requiring an account in the system.

  • ClearCompany SSO Login: Security control requiring an account in the system.

  • EAB Navigate (Staff tile): Users get shown the staff tile shortcut in myGRCC.

  • GoFMX SSO Login: Security control requiring an account in the system.

  • VMWARE Horizon: Access to the staff remote pool.

  • KnowBe4 Training SSO Login: Security control requiring an account in the system.

  • LinkedIn Learning: Access through the staff and student group.

  • Zoom Phone SSO Only: Security control requiring an account in the system.

 

Student Group Membership

The Student group (ActiveStudents.replicated.groups.data) is a user security group used to flag individuals as students within SuperVault. This flag is replicated to both active directory domains (ad.grcc.edu and in.grcc.edu). Users are added once daily through an update job checking for the combination of Student Mailbox and Workstation Services entitlements. Manual additions can be done by Support Desk staff.

Permissions and access control

Student group members have limited specific access, as most resources used by students are also used by staff. However, one notable access is:

  • Student E-mail tile in MyGRCC: This shortcut is added by the student group.