When an organization owner creates a custom group and associates it with other organizations, the group becomes shared. The organization owners of the target organizations receive an email invitation from the source organization's owner to import the shared group and assign service roles.

As an organization owner receiving the invitation to import a shared group created in a different organization, you assign service roles for the shared group while importing it to your organization.

You can distinguish imported shared groups from shared groups created in your organization by their label:.

The members of the shared group you imported can use the services in your organization according to the roles you assigned to the group. This allows cross-organization access to services at the group level and removes the need to send individual invitations to each user.
Important: Shared groups imported from other organizations cannot be edited. You can edit the roles you assign to the shared group or remove the group from your organization.

Prerequisites

You must know the name or the organization ID of the source organization that created the shared group you want to add.

Procedure

  1. From the Carbon Black Cloud console, click the VMware Cloud Services Application Menu in the top-right corner and select Identity & Access Management.
  2. From the left menu, select Groups and then select Add Groups.
  3. Select Import groups from other organizations, and click Continue.
  4. From the drop-down list, select the source organization that created the shared group.
  5. Select the shared group you want to import.
  6. Select an organization role to assign the selected group access to your organization.
  7. Click Add service access to assign service roles to the selected group:
    1. Use the drop down menu to select the service in your organization you want the shared group to access.
    2. Click the roles box and select the service roles you want to assign to the shared group.
    3. Define the time period for the access. You may choose an end date or provide a non-expiration access.
  8. To add access to an additional service, click Add service access and repeat steps 7.a through 7.c.
  9. Optionally, assign a Custom Role to the group by clicking Add Custom Role Access.
  10. Leave the Send emails to all invited users notifying them of this role assignment checked if you want all members of the shared group to receive invitations to access your service.
  11. Click Import.

Results

The shared group is added as a custom remote group to your organization.

What to do next

To return to the Carbon Black Cloud console, click Services and then launch the Carbon Black Cloud service.