DocumentationAPI ReferenceRelease Notes
API Reference

Create new user group

Required Permission(s)

  • User Accounts Management (Full control)

Notes

  • Creating a user group that has the Secrets Safe feature/permission enabled requires the caller to be an administrator.
Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

The user group creation model containing name, description, and configuration

boolean

The group's active status

string | null

The group's type out of the available group types (BeyondInsight, EntraID, ActiveDirectory, LdapDirectory)

string | null

The group's name

string | null

The group's description

string | null

The group's distinguished name

string | null

The directory server host name or IP (LdapDirectory group type only)

int32

The group's port (LdapDirectory group type only)

boolean

Flag indicating whether to use SSL (required if bindUser is given)

string | null

Username for directory binding. If not given, attempts to use existing credentials for the directory. If specifying an existing credential, you also need Credential Management – Read. If specifying a new credential, you also need Credential Management – Read/Write (ActiveDirectory and LdapDirectory group types only)

string | null

Password for directory binding (required if bindUser is given

string | null

Directory group membership attribute (LdapDirectory group type only)

string | null

Directory account naming attribute (LdapDirectory group type only)

string | null

The group's base distinguished name

string | null

The directory forest name (required when bindUser is given, ActiveDirectory group type only)

string | null

The group's domain name (ActiveDirectory group type only)

boolean

Flag indicating if the Active Directory group uses the global group synchronization settings (ActiveDirectory group type only)

boolean

Flag indicating if the Active Directory group overrides the global group synchronization settings (ActiveDirectory group type only)

string | null

Unique identifier for EntraId app. If not given, attempts to use existing credentials for the directory. If specifying an existing credential, you also need Credential Management – Read. If specifying a new credential, you also need Credential Management – Read/Write (EntraId group type only)

string | null

Client credential (EntraId group type only)

string | null

The group's tenant ID (EntraId group type only)

string | null

Can have values of “AzureUsGovernment”, “AzurePublic”, or null. If the AzureInstance value is not provided or if it’s null, the instance defaults to AzurePublic unless the credential already exists. At that point it will take on the value of the existing credential (EntraId group type only)

Permissions
array of objects | null

One or more permissions and access levels to set for the new user group

Permissions
SmartRuleAccess
array of objects | null

One or more Smart Rules and access levels to set for the new user group

SmartRuleAccess
ApplicationRegistrationIDs
array of int32s | null

Zero or more IDs representing the API application registrations to grant the new user group. If given, enables API for the user group

ApplicationRegistrationIDs
Headers
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.