cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
67
Views
1
Helpful
1
Replies

Managing Group-Based Access Without Disabling User Accounts

Norbert Szasz
Community Member

Hello,

We have two separate environments for our staging and production systems. Some teams are assigned to both environments, while others are restricted to only one. As a result, users can be members of multiple groups.

From time to time, certain groups are disabled, preventing their members from accessing the associated environment.

However, when I disable a group, the users within that group also get disabled. Even if a user belongs to another active group assigned to an application, their access is denied because their account is disabled.

Is it possible to achieve this functionality using groups, or would you suggest an alternative approach to manage access without disabling user accounts?

Looking forward to your advice.

Best regards,
Norbert

 

1 Accepted Solution

Accepted Solutions

DuoKristina
Cisco Employee
Cisco Employee

Could you manage this at the individual Duo application level with the user access control? Instead of disabling the group maybe just remove the group from the access list for the application?

Duo, not DUO.

View solution in original post

1 Reply 1

DuoKristina
Cisco Employee
Cisco Employee

Could you manage this at the individual Duo application level with the user access control? Instead of disabling the group maybe just remove the group from the access list for the application?

Duo, not DUO.
Quick Links