管理组Manage groups

使用组可以将相同的权利分配给多个用户。Groups let you assign the same entitlements to multiple users. 作为管理员用户,你可以使用管理控制台组 APISCIM API支持 SCIM 的标识提供者(例如 Azure Active Directory)来管理组。As an admin user, you can manage groups using the Admin Console, the Groups API, the SCIM API, or a SCIM-enabled Identity Provider like Azure Active Directory. 本文介绍了如何使用管理控制台来管理组。This article discusses group management using the Admin Console.

“组”选项卡Groups tab

使用管理控制台,你可以:Using the Admin Console, you can:

  • 添加组。Add groups.
  • 将用户添加到组以及删除用户。Add users to groups and remove them.
  • 将组添加到其他组以及删除组。Add groups to other groups and remove them.
  • 授予和撤销为所有组成员创建群集的权限(如果已为工作区启用了群集访问控制)。Grant and revoke the ability to create clusters for all group members (if Cluster access control has been enabled for the workspace).
  • 通过将用户添加到管理员组或删除他们来管理管理员权限。Manage administrator rights by adding users to the admins group or removing them. (你还可以使用用户管理界面将用户分配到管理员组。)(You can also assign a user to the admins group using the User management interface.)

备注

在工作区资源上具有“参与者”或“所有者”角色的用户会自动分配给管理员组。Users with the Contributor or Owner role on the workspace resource are automatically assigned to the admins group. 有关详细信息,请参阅分配帐户管理员For more information, see Assign account admins.

添加组 Add a group

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.

  2. 单击“+ 创建组”。Click + Create Group.

  3. 输入组名称,然后单击“确认”。Enter a group name and click Confirm.

    组名称必须是唯一的。Group names must be unique. 你无法更改组名称。You cannot change a group name. 如果要更改某个组名称,则必须删除该组,然后使用新名称重新创建它。If you want to change a group name, you must delete the group and recreate it with the new name.

向组添加用户和子组Add users and child groups to a group

备注

不能向管理员组添加子组。You cannot add a child group to the admins group.

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.
  2. 选择要更新的组。Select the group you want to update.
  3. 在“成员”选项卡上,单击“+添加用户或组”。On the Members tab, click +Add users or groups.
  4. 在“添加用户或组”对话框中,单击向下箭头以显示用户和组的下拉列表,然后选择要添加的用户和组。On the Add users or groups dialog, click the down arrow to display a drop-down list of users and groups, and select the ones you want to add.
  5. 单击向下箭头以隐藏下拉列表,然后单击“确认”。Click the down arrow to hide the drop-down list and click Confirm.

向组添加权利Add entitlements to a group

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.

  2. 选择要更新的组。Select the group you want to update.

  3. 在“权利”选项卡上,选择要向组中的所有用户授予的权利。On the Entitlements tab, select the entitlement you want to grant to all users in the group.

    “允许创建群集”是唯一可授予的权利,但将来会添加其他权利。Allow cluster creation is the only entitlement available to grant, although others will be added in the future. 向用户授予此权利后,将允许用户创建和启动新群集。When you grant this entitlement to users, they are allowed to create and launch new clusters. 你可以使用群集级权限限制对现有群集的访问。You can restrict access to existing clusters using cluster-level permissions.

  4. 在确认对话框中,单击“确认”。On the confirmation dialog, click Confirm.

查看父组View parent groups

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.
  2. 选择要更新的组。Select the group you want to update.
  3. 在“父级”选项卡上,查看你的组的父组。On the Parents tab, view the parent groups for your group.

删除用户或子组 Remove a user or child group

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.
  2. 选择要更新的组。Select the group you want to update.
  3. 在“成员”选项卡上,找到要删除的用户或组,然后单击“操作”列中的 XOn the Members tab, find the user or group you want to remove and click the X in the Actions column.
  4. 单击“删除成员”以进行确认。Click Remove Member to confirm.

用户或子组将丢失此组中的成员身份所授予的所有权利和子组成员身份。The user or child group loses all entitlements and child group memberships granted by virtue of membership in this group. 但请注意,他们可能会通过其他组或用户级别的授予中的成员身份保留这些权利。Be aware, however, that they may retain those entitlements by virtue of membership in other groups or user-level grants.

删除权利Remove an entitlement

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.
  2. 选择要更新的组。Select the group you want to update.
  3. 在“权利”选项卡上,清除要为组中的所有用户撤销的权利的复选框。On the Entitlements tab, clear the checkbox for the entitlement you want to revoke for all users in the group.
  4. 在确认对话框中,单击“删除”。On the confirmation dialog, click Remove.

组成员将失去权利,除非他们具有作为单个用户或通过其他组成员身份获得的权限。Group members lose the entitlement, unless they have permission granted as an individual user or through another group membership.

将组从其父组中删除Remove a group from its parent group

  1. 转到管理控制台,然后单击“组”选项卡。Go to the Admin Console and click the Groups tab.
  2. 选择要更新的组。Select the group you want to update.
  3. 在“父级”选项卡上,找到你要从中脱离的父组,然后单击“操作”列中的 XOn the Parents tab, find the parent group you want to secede from and click the X in the Actions column.
  4. 在确认对话框中,单击“删除父级”。On the confirmation dialog, click Remove parent.

分配给父组的所有权利将从组的成员中删除。All entitlements assigned to the parent group are removed from the members of the group. 但请注意,他们可能会通过其他组或用户级别的授予中的成员身份保留这些权利。Be aware, however, that they may retain those entitlements by virtue of membership in other groups or user-level grants.