HEX
Server: Apache/2.4.63 (Unix)
System: Linux TOMS-220NAS 4.4.302+ #86009 SMP Wed Nov 26 18:19:17 CST 2025 x86_64
User: flavio87 (1026)
PHP: 8.3.27
Disabled: NONE
Upload Files
File: /volume1/@appstore/CMS/ui/help/enu/cms_gpo.html
<!DOCTYPE html>
<html class="img-no-display">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" >
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<title>Synology CMS</title>
<link href="../../../../help/help.css" type="text/css" rel="stylesheet"  />
<link href="../../../../help/scrollbar/flexcroll.css" type="text/css" rel="stylesheet"  />
<script type="text/javascript" src="../../../../help/scrollbar/flexcroll.js"></script>
<script type="text/javascript" src="../../../../help/scrollbar/initFlexcroll.js"></script>
</head>
<body><h1>Group</h1>

	<p>The <b>Group</b> page offers features for organizing the managed servers into server groups and apply policies to server groups, thereby simplifying management and applying the same settings to all the servers in a group. Each server can only be added to one group. The parent group <b>All Servers</b> exists by default, and child groups can be created under the parent group. This article guides you through how to create, edit, delete, view, and filter server groups.</p>


<h4>To create a group:</h4>

<ol>
<li>Click <strong>Create</strong>.</li>
<li>Enter the group name and description, and select the servers that you want to add to the group. Click <b>Next</b>.
<br /><span class="note_head">Note:</span> Each server can only be added to one group.	
</li>
<li>Configure group policies. Please refer to the section <a href="#t5">To configure group policies</a> for details.</li>
<li>Click <b>Next</b>.</li>		
<li>Assign group administrators by selecting one or multiple groups <img class="inline" style="vertical-align:middle" src="../image/grid_icn_group.png" width="" height="15"  /> or users <img class="inline" style="vertical-align:middle" src="../image/grid_icn_users.png" width="" height="15"  /> from the drop-down menu, and click <img class="inline" style="vertical-align:middle" src="../image/CMS_admin.png" width="" height="15"  /> to add it to the list. Click <img class="inline" style="vertical-align:middle" src="../image/CMS_admin_delete.png" width="" height="15"  /> to remove the administrator from the list. Click <b>Apply</b> to finish.
<br /><span class="note_head">Note:</span> Refer to the section <a href="#t3">To delegate management permissions</a> for details.	
</li>	
</ol>

	
<h4 class="list_head"><a name="t5" id="t5">To configure group policies:</a></h4>
<p>The policy page contains three sections, namely, <b>Locked Global Policies</b>, <b>Customize Group Policies</b>, and <b>Unlocked Global Policies</b>. This page appears when you create a new group by clicking <b>Group</b> > <b>Create</b>, or when you want to edit a created policy by clicking <b>Group</b> > <b>Edit</b> > <b>Policy</b>.</p>
	<ul>
	<li><b>Locked Global Policies</b>: This section displays the locked policies applied to all the managed servers.</li>
	<li><b>Customize Group Policies</b>: This section allows you to add, delete, and prioritize the custom policies applied to this group.
		<ul>
		<li><b>Add</b>: Click the button to add one or more policies. You can enter the keyword in the search bar to quickly find a specific policy. Policies that have already been added to other groups are in grey and cannot be selected. Tick the checkbox to select one or more policies.</li>
		<li><b>Delete</b>: Select a policy and click the button to delete it.</li>
		<li><b>View</b>: Select a policy and click the button to view its details.</li>
		<li><b>Prioritize</b>: Drag the icon <img class="inline" style="vertical-align:middle" src="../image/CMS_prioritize.png" width="" height="15" /> up or down the list to adjust the order of a policy.</li>
		<li><b>Locked</b>: Tick this checkbox to lock an added policy.
		<br /><span class="note_head">Note:</span> Ticking the <b>Locked</b> checkbox will force all servers of a group to inherit the locked policies. Keeping the checkbox unticked allows the servers to choose whether to inherit a policy. The priority of a locked policy will always be higher than an unlocked policy.
		</li>	
		</ul>	
	</li>
		<li><b>Unlocked Global Policies</b>: This section displays the unlocked policies applied to all the managed servers. You can choose whether a group should inherit all the unlocked global policies.</li>
	</ul> 
	
<div class="section">
<h4>Note:</h4>
<ul>
	<li>The policies in <b>Locked Global Policies</b> will take the highest priority, followed by those in <b>Customize Group Policies</b>, and by <b>Unlocked Global Policies</b>.</li>
	<li>The Arabic numerals listed in front of the policies refer to the priority of the policies. That is, if a policy listed <b>2</b> conflicts with a policy listed <b>3</b>, then the policy listed <b>2</b> will take priority and be applied.</li>
	<li>Example: If Locked Global Policies contains a policy for enabling SMB (listed with the Arabic numeral 2), whereas Customize Group Policies contains a policy for disabling SMB (listed with the Arabic numeral 3), then SMB will be enabled on all servers in the group instead of being disabled.</li>
</ul>
</div>


	
	
<h4>To manage a group:</h4>
<p>Other options are offered for managing the groups. Please select a group and click the <b>Edit</b>, <b>Delete</b>, or <b>View</b> buttons to further manage it.</p>

	<ul>
		<li><b>Edit</b>:
			<ul>
			<li><b>General</b>: Go to this tab to edit the group name and description.</li>
			<p>
				<span class="note_head">Note:</span> Group name and description cannot be edited if the <b>All Servers</b> group is selected because the group name and description are both "All Servers" by default.
			</p>
			<li><b>Members</b>: Go to this tab to add or remove members.<br />
				<span class="note_head">Note:</span> This tab will not appear if the <b>All Servers</b> group is selected because all the managed servers are added as members by default.</li>
			<li><b>Policy</b>: Go to this tab to add, delete, view, lock, or unlock a policy. Refer to the section <a href="#t5">To configure group policies</a> for details. </li>
				<li><b>Administrators</b>: Go to this tab to delegate management permissions to groups or users. Refer to the section <a href="#t3">To delegate management permissions</a> for details. </li>

	        </ul>
		</li>
		<li><b>Delete</b>: Confirm that you want to delete the group and click <b>Delete</b>.</li>
		<li><b>View</b>: Click to view information of the members, administrators, and rules of the applied policies.<br />
			<span class="note_head">Note:</span> The policy information shown here is different from that shown in <b>Edit</b>. The <b>Policy</b> page in <b>View</b> shows the rules of the policy, while that in the <b>Edit</b> page shows the policy.   
		</li>
	</ul>

	<h4 class="list_head"><a name="t3" id="t3">To delegate management permissions:</a></h4>

<p>Management permissions of server groups can be delegated to users or groups. After launching CMS, the user can view and modify the settings of servers that he/she has been delegated management permissions (such as the settings at <strong>Server</strong>, <strong>Notifications</strong>, <strong>Logs</strong>, <strong>Group</strong>, and <strong>Policy</strong>). </p>

<ol>
<li>Select a group and click <strong>Edit</strong> > <strong>Administrators</strong>. </li>
<li>Add the users or groups that you want to delegate management permissions by selecting one or multiple groups <img class="inline" style="vertical-align:middle" src="../image/grid_icn_group.png" width="" height="15"  /> or users <img class="inline" style="vertical-align:middle" src="../image/grid_icn_users.png" width="" height="15"  /> from the drop-down menu, and click <img class="inline" style="vertical-align:middle" src="../image/CMS_admin.png" width="" height="15"  /> to add it to the list. Click <img class="inline" style="vertical-align:middle" src="../image/CMS_admin_delete.png" width="" height="15"  /> to remove the administrator from the list.</li>
<li>Click <b>Save</b> to finish.</li>
</ol>

<div class="section">
<h4>Note:</h4>
<ul>
	<li>Users belonging to the <strong>administrators</strong> group can view and modify settings of all managed servers. Users who do not belong to <strong>administrators</strong> group can only view and modify settings of managed servers that they have been delegated management permissions.</li>

</ul>
</div></body>
</html>