Groups are collections of items, often related to a specific region, subject, or project, that are created and managed by the group owner. If you have privileges to create groups, you decide who can find your groups, whether others can request to join, whether members can update items shared with the group, who can contribute content, and the type of items (for example, maps or layers) displayed by default in the group. You also have control over items shared with the group and can invite others to join, even if your group doesn't accept membership requests. Default administrators can also restrict who can see the list of group members and restrict members from leaving the group (administrative groups).
Organization administrators also use groups to configure the portal website. These site configuration groups contain the organization's featured content, basemaps, and templates.
Create a group
To create a group, complete the following steps:
- Verify that you are signed in and have privileges to create groups.
- Click Groups at the top of the site and click Create group on the My Groups tab.
- Add a thumbnail image to represent the group.
You can drag an image or browse to a file. For best results, add an image that is 400 by 400 pixels or larger with an aspect ratio of 1:1 in a web file format such as PNG, JPEG, or GIF. Pan and zoom to what you want to appear in your thumbnail. Depending on the size and resolution of your image file and how far you zoom in to customize the thumbnail, the image may be resampled and scaled when it's saved. If you add an image in GIF or JPEG format, it will be converted to PNG when it's saved.
- Provide a group name and tags. You can also add a short summary.
- For Who can view this group?, select one of the following:
- Only group members—Only members of the group can find and view the group. Members must be invited to join the group.
- People in the organization—Only members of the organization can find and view the group. Members can be invited to the group or apply to join.
- Everyone (public)—Anyone with access to the portal, even if they are not a member of the portal organization, can search for and view the group and access any content that is shared with both the group and the public. This is the default.
If your group will contain curated content to feature on your organization's Gallery page, select the option most appropriate for your intended audience. If you expect public visitors to view the gallery, select Everyone (public). Select People in the organization if you expect organization members to visit. Whether content items appear in the gallery also depends on how the items are shared.
- Select one of the following to specify who can join the group:
- Those who request membership and are approved by a group manager—Only members who request to join the group and are approved by the group owner or a group manager can join the group.
- Only those invited by a group manager—Only members who are invited by the group owner or a group manager can join the group.
Members of an enterprise group—Membership is controlled outside of the portal by an enterprise group. This option is only available if you are an administrator of the organization or have the privilege to link built-in groups to enterprise groups. The exact process to configure this depends on whether your IDP is AD/LDAP based or SAML based; see the About linking enterprise groups section below.
- Anyone—Any organization member can join the group without being invited or approved. Members who click Join this Group on the group page are instantly granted membership in the group.
The options you see depend on the option you selected in the previous step and your privileges. Note that you only see the third option if your portal is configured to use enterprise groups. Also note that if you chose to allow Everyone (public) to view the group, regardless of the following option you choose, people who are not signed in to the portal cannot join the group, and they cannot be invited to groups unless they are members of your portal organization.
- For Who can contribute content to the group?, select one of the following:
- Group members—All group members can contribute content to the group.
- Only group owner and managers—Only you (the group owner) and group managers can contribute content to the group. If you choose this option, members can view and access your items, but they can't share their own items with the group. This type of group is a good way to share your authoritative maps and data to a targeted audience. You control what items appear in the group and who can view them.
- For What items in the group can its members update?, select one of the following:
This setting is only available if you have privileges to create groups with update capabilities. Updates to an item include changes to the item details and updates to the content. This setting is only available when creating new groups and when membership in the group is only open to those who are invited or request and are approved to join.
- Only their own items—Group members can update only the items they own.
- All items (group membership is limited to the organization)—Group members can update any items shared with the group, which includes modifying the item details and updating the content. If you choose this option, the group becomes a shared update group, which limits group membership to members of your organization who have privileges to create, update, and delete content.
Only the owner (or administrator) of the item can perform the following actions on the item (not all actions apply to all item types): delete, share, move, change owner, change delete protection, publish, register an app, overwrite data in hosted feature layers, and manage tiles in hosted tile layers. However, members of this shared update group have other administrator types of privileges depending on the item type and the app used to access the item.
- For Who can see the list of members on the Members tab?, choose one of the following:
This setting is only available to default administrators.
- All group members—All group members can see the list of group members.
- Only group owner and managers—Only the group owner and managers, and those with administrative privileges to view all members and groups, can see the full list of group members. Other members of the group will only see the group owner and group managers listed on the Members tab.
The item owner will still be displayed on the item page of individual items in the group. This option only applies to the Members tab of the group page. Organization members will be able to see the group as a filtering option when inviting members to a group or when managing members from the organization page Members tab.
- To change how the items are sorted on the group page, select a field from the drop-down menu.
You can choose to sort by title (default), owner, view count, or date modified. To change how the items are ordered, check or uncheck the Ascending box. The sort field and order extend to your group when it is embedded in a website, shared as an app, and used to configure your portal website (such as the basemap gallery). If you change the sort field or order, the item display is updated everywhere the group is used.
- Specify the type of items (for example, maps or layers) you want to display by default on the group's Content and Overview tabs.
- If you are a default administrator and want to restrict group members from leaving the group, check the box under Administrative group. If you check this box, group members can only leave the group if the group owner or a group manager removes them.
This setting is only available when creating new groups.
- Click Create Group.
Your new group is created with the basic information and properties you specified. It is recommended that you add a brief summary about the group (if you have not already done so), as well as an in-depth description.
Your group is ready to be used. You can edit group properties on the Overview tab and group settings on the Settings tabs. Use the Invite Users button on the Overview tab or the Members tab to search for and invite members to the group.
Link enterprise groups from an IDP
If you have a Windows AD-, LDAP-, or SAML-based IDP that manages enterprise groups for your organization, you can link these groups to new groups you create in your ArcGIS Enterprise portal. When selecting who can join your new group in the above workflow, note these additional steps:
AD- or LDAP-based IDPs
If your portal is configured with an enterprise identity store, and metadata has been provided about the enterprise groups in the identity store, you can set membership in a new portal group to members of an existing enterprise group. To define an enterprise group, type all or part of an enterprise group name in the text box and click Search for Group. Select the desired group from the list of results and click Select Group.
Any of the enterprise accounts in this enterprise group that are already portal members are added to the portal group as soon as it is created. If your enterprise accounts and groups are from a Windows AD server, this includes accounts from nested enterprise groups.
The AD group Domain Users should not be used as an enterprise group. This is because it is considered the primary group for most AD users and is not listed in the memberOf attribute for most users.
To link enterprise groups from a SAML-based IDP to new groups created in your portal, check the Enable SAML based group membership box when setting your IDP in the portal's settings. To link an enterprise group, enter the name of the group exactly as it will be returned in the IDP's SAML assertion response when creating your new group in the ArcGIS Enterprise portal. The Search for Group option is not available when Enable SAML based group membership is selected.
The supported (case-insensitive) names for the attribute defining a user's group membership are Group, Groups, Roles, MemberOf, member-of, http://schemas.xmlsoap.org/claims/Group, http://schemas.microsoft.com/ws/2008/06/identity/claims/groups, urn:oid:22.214.171.124.4.1.59126.96.36.199.1, and urn:oid:2.16.840.1.1137188.8.131.52.1.25.
For enterprise groups obtained via the IDP's SAML assertion response, each user's group membership is only updated each time the user signs in to the portal.
Edit group properties and settings
After creating a group, you, any group managers you designate, and administrators with group privileges can edit its properties and settings. For example, you can modify the group title or description, as well as change settings such as who can contribute content. For more information on working with groups you own, including managing group content and members, see Own groups.
- Verify that you are signed in as the owner, group manager, or administrator of the group you want to edit.
- Click Groups at the top of the site, and use the tabs, filters, sort options, and search as needed to find the group you want to edit.
- Click the name of the group to open its group page and do any of the following:
- On the Overview tab, click Edit next to the property you want to edit (for example, the description or tags), make your changes, and click Save to save your changes. You can edit the group name, summary, description, thumbnail, and tags.
- On the Settings tab, modify the group settings (for example, how group content is sorted, who can view the group, who can join the group, or who can contribute content). You can also specify the type of items (for example, maps or layers) you want to display by default on the group's Content and Overview tabs. When you're finished, click Save on the Settings tab.
Your ability to edit some settings depends on your privileges and group role. With existing groups, you cannot change the What items in the group can its members update? setting and the Administrative group setting that restricts members from leaving the group. These settings are only available for new groups. If you want to change any of these settings, you must delete the group and create a new one with the option you want.
Shared update groups
Organization administrators can create groups that allow members to update items that are shared with the group. These shared update groups are useful in collaborative situations in which multiple people need to update the same item—for example, shift workers in operations centers who need to update the maps underlying their apps and dashboards.
When members share an item with a shared update group, they remain the owner of the item. Other group members can update the item. Updates to an item include changes to the item details and updates to the content. For example, they can add layers to a map and save the map with the updated content.
To make your group a shared update group, select the All items option for the What items in the group can its members update? setting when creating the group.
At this time, shared update groups are intended for updating item details and the contents of maps, apps, and scenes. Some updates are reserved for the item owner or administrator (such as moving, sharing, or deleting an item and changing ownership). However, members of this group also have elevated privileges, such as the ability to edit the contents of hosted feature layers, alter editor tracking settings, enable or disable attachments, and alter the layer's schema. Therefore, proceed with caution when adding members to this type of group. Currently, most ArcGIS apps do not support updating items shared with a shared update group. To determine whether this capability is supported in a specific ArcGIS app, refer to its product documentation.