For highly sensitive data, it may be advisable to carry out pre-authorization, e.g. in the form of anti-sabotage or confidentiality training, in addition to complying with the need-to-know principle. At the same time, it is important to ensure that only those employees who have completed this pre-authorization are granted access permissions.
In order to technically map such organizational protective measures, it is now possible to define AD groups for data protection classes that contain the pre-authorized employees.
If a resource is marked with this data protection group, the system guarantees that only those permissions are transferred to the target system that have been authorized by AD group membership. Unauthorized users are highlighted in the user interface. If they are later added to the group, the permission is transferred to the target system during the next job run.