Inherited permissions

When access rights are set for a group, they apply to every process, object, or resource in that group, including all child groups and their contents. This also applies when moving groups and items to another group – all items inherit the permissions of the group they are moved to, overwriting any permissions already applied. Each time a group or item is moved and the permissions are changed, a message box displays informing that the move will have an impact.

If a group is unrestricted, the Access Rights for child groups can be set as required, for restricted groups, the Access Rights for child groups can be viewed but not edited.

Moving groups

To move groups the following permissions are required and must be enabled in the user's security role permissions so they can be applied at group level as required:

  • Edit group permissions are required to move any group.
  • Manage Access Rights and Edit group permissions are required to move a restricted group to a different parent or ancestor group. To move a restricted group within the same restricted ancestor, no additional permissions are required as the groups already share the same inherited permissions.

Groups can be directly and indirectly restricted:

  • Directly – Permissions are determined by the access rights applied specifically to that group.
  • Indirectly – Permissions are determined by the access rights applied to a parent group.

The impact of moving to and from groups with different access levels is explained in the following tables.