Hi,
I have made some rules on Viya that allow members of a self-made User Admin group (UG_UserAdmin_<group1>) to manage another usergroup (UG_<group1>).
Object uri | Principal | Setting | Permissions | Description |
/identities/groups/UG_<group1>/userMembers/* | UG_UserAdmin_<group1> | Grant | Create, Update, Delete | UG_UserAdmin_<group1> can add or remove members of the UG_<group1> group |
/identities/groups/UG_<group1> | UG_UserAdmin_<group1> | Grant | Read | UG_UserAdmin_<group1> see the UG_<group1> group |
We have sets of rules like this for many different User Groups & corresponding User Admin Groups. This works like intended, but I would like to create a Global User Admin Group, that can administer all User groups. I know I can make this Global User Admin Group member of all individual User Admin Groups, but in some cases a User group does not have a User Administrator group, but I still want the Global User Admin Group to be able to administer this group. Allowing the Global User Admin Group to administer ALL groups would not be an option either, because the Global User Admin Group should only be allowed to administer a selection of the groups.
Is it possible to create a rule that is applied to Object Uri's following a certain naming convention. For example, I would like to apply a rule to every Object uri containing a certain substring ("/identities/groups/UG_" in this example)