<main>
<article class="userContent">
<p><br></p><h2 data-id="general">General</h2><div class="blockquote"><div class="blockquote-content"><p class="blockquote-line"><em>This article applies to TeamViewer customers with a Tensor license. </em></p></div></div><p>User groups are automatically created and maintained via the same integrations you can use for account creation, like SCIM configurations for <a href="https://community.teamviewer.com/English/kb/articles/61583-scim-configuration-for-okta" rel="nofollow noreferrer ugc">Okta</a>, <a href="https://community.teamviewer.com/English/kb/articles/59181-scim-configuration-for-azure-active-directory" rel="nofollow noreferrer ugc">Azure Active Directory</a>, etc. <a href="https://www.teamviewer.com/en/integrations/active-directory/" rel="nofollow noreferrer ugc">AD Connector</a> or <a href="https://webapi.teamviewer.com/api/v1/docs/index" rel="nofollow noreferrer ugc">API</a>.</p><p>Please note that SCIM configurations are only available for customers with a Tensor license.</p><p><br></p><h3></h3><h2 data-id="user-groups">User Groups</h2><h3 data-id="location">Location</h3><p>User groups are available in the <strong>User Management</strong> within the Management Console. </p><p><strong>📌Note</strong>: To see the user groups, please activate the toggle <strong>Show User Groups</strong>.</p><p>Administrators can use User Groups to filter the list of users in a company profile quickly. </p><div class="embedExternal embedImage display-large float-none">
<div class="embedExternal-content">
<a class="embedImage-link" href="https://us.v-cdn.net/6032394/uploads/J3H1E9T686HG/image.png" rel="nofollow noreferrer noopener ugc" target="_blank">
<img class="embedImage-img" src="https://us.v-cdn.net/6032394/uploads/J3H1E9T686HG/image.png" alt="image.png" height="638" width="1157" loading="lazy" data-display-size="large" data-float="none"></img></a>
</div>
</div>
<p><br></p><h3 data-id="-1"></h3><h2 data-id="maintaining-teamviewer-account-in-user-groups">Maintaining TeamViewer Account in User Groups</h2><p>Accounts are added, moved, and deleted via the abovementioned integrations. Any changes you make in Okta, Azure, etc., are being reflected automatically in the Management Console. </p><p>📌<strong>Please note</strong>: The Management Console does <strong>not </strong>offer any buttons or menus to do this manually.</p><p>📌 <strong>Note</strong>: Only integration into Identity Providers like Azure Active Directory or Okta provides for full automation. The <a href="https://community.teamviewer.com/English/kb/articles/31158-active-directory-connector-ad-connector" rel="nofollow noreferrer ugc">AD Connector</a> provides some guidance but still requires manual work and skill to get the work done. The API is only recommended to administrators who know how to work with APIs. </p><p><br></p><h3 data-id="-2"></h3><h2 data-id="assigning-users-from-ad-to-a-user-group">Assigning users from AD to a user group</h2><h3 data-id="pre-defined-user-groups">Pre-defined user groups</h3><p>There are 3 pre-defined user group name spaces in the MCO:</p><ol><li>"CompanyAdmin_ADsync".</li><li>"Admin_ADsync".</li><li>"User_ADsync".</li></ol><p>Each of these 3 user groups has its own set of permissions. When putting a user in your AD into one of these groups and synchronizing these groups and their users via the ADSync to the Management Console, the users will get the permissions tied to the user group:</p><ol><li>Every user moved into the user group "CompanyAdmin_ADsync" will get company administrator permissions.</li><li>Every user moved into the user group "Admin_ADsync" will get user administrator permissions.</li><li>Every user moved into the user group "User_ADsync" will get member permissions.</li></ol><p>When you move a user out of one of these groups, it will keep its permissions as long as you don't move it into one of the other pre-defined groups (via the ADSync).</p><p><br></p><h3 data-id="-3"></h3><h2 data-id="filtering">Filtering </h2><p>With User Groups, you can easily filter the list of users in your company profile. </p><p>By clicking on one of the available groups, the accounts that belong to the group will immediately be showcased.</p><p>This also allows you to select specific users where you want to bulk change permissions and settings within the Management Console. <a href="https://community.teamviewer.com/English/kb/articles/108874-user-roles" rel="nofollow noreferrer ugc">Learn more here</a>.</p><p><br></p><h3 data-id="-4"></h3><h2 data-id="event-log">Event Log</h2><p>For Tensor customers, all changes to the User Groups via AD, API, and SCIM will be logged in the Event log. </p><p>Learn more about the <a href="https://community.teamviewer.com/English/kb/articles/54970-auditability-event-log" rel="nofollow noreferrer ugc">Event Log here</a>.</p>
</article>
</main>