Guides
  • Guides
  • Tutorials
    • File Management
    • Manage Identities
    • Storage Connectors
    • Automation with Flows
  • Overviews & Concepts
    • Clients, Scopes, and Consents
    • Collections and Endpoints
    • Globus Auth Requirements Errors (GAREs)
    • High Assurance Collections for Protected Data
    • Security Overview
  • Recipes & Manuals
    • Automating Transfer and Share of Data from Instruments
    • Automation with Service Accounts
    • GCS Apache Reverse Proxy
    • GCS Default VirtualHost
    • Monitoring Globus Connect Server
    • MRDP
    • Require a Flow for Data Movement
    • Use Globus Preview
Skip to main content
Globus Docs
  • Getting Started
    Getting Started

    Getting Started and Tutorial docs cover how to perform some activity or provide an introduction to a feature. They are not comprehensive, but help you get started with Globus or with new Globus features.

    • Users
    • Admins
    • Developers
  • Reference
    Reference
    • Service
      • Auth
      • Groups
      • Transfer
      • Timers
      • Flows
      • Compute
      • Search
    • Agents
      • Globus Connect Server
      • GCS CLI
      • Globus Connect Personal
      • Globus Compute
    • SDK
      • Python
      • JS
    • Clients
      • CLI
    • Security and Compliance
      • Product Security
      • Privacy
      • Solutions for Sensitive Data
      • FAQs
  • Solutions & Guides
    Solutions & Guides

    Find practical approaches for leveraging Globus in research environments, integrating with platforms, and building science gateways. Access hands-on guides, integration instructions, and real-world scenarios for advanced usage.

    • Portals/Science Gateways
    • Guides
  • Support
    Support

    Find answers to frequently asked questions, connect with the community by joining our mailing lists, or reach out directly to Globus support.

    • FAQs
    • Mailing Lists
    • Contact Us
    • Check Support Tickets
  • Site Search
  1. Home
  2. Guides
  3. Tutorials
  4. Manage Identities
  5. Mark a Group as High-Assurance

Designate a high-assurance group for use with restricted data

When managing access to restricted data in guest collections, permissions may assign access to groups as well as to individuals. Each group must be flagged as a high-assurance group.

To designate a high-assurance group, locate the group in the Groups section of the Globus Web App. If the group isn’t listed on the main page, search for it by name.

Search for a group

Once you’ve located the group, click the group’s name to view its configuration, then click "Settings" to open the Settings tab. In the "Policies" section, click "Edit Policies."

Edit the group's policies

Near the end of the list of policies, find "Session enforcement for this group is." The two options are "not strict" (the default) and "strict." Change the policy to "strict" to designate that this is a high-assurance group. Change the authentication duration (defaults to 28800 seconds, or eight hours) to the value required by your institution. Click "Submit."

Set strict session enforcement

At this point, your group is now designated for high-assurance use.

When you return to the group settings page, you may see a notice that you must authenticate as a specific identity to make further changes to the group. Because the group is now using strict authentication, this is expected if you haven’t authenticated to the required identity in the current session. Follow the prompts to re-authenticate.

Required identity
  • Guides
  • Tutorials
    • File Management
    • Manage Identities
    • Storage Connectors
    • Automation with Flows
  • Overviews & Concepts
    • Clients, Scopes, and Consents
    • Collections and Endpoints
    • Globus Auth Requirements Errors (GAREs)
    • High Assurance Collections for Protected Data
    • Security Overview
  • Recipes & Manuals
    • Automating Transfer and Share of Data from Instruments
    • Automation with Service Accounts
    • GCS Apache Reverse Proxy
    • GCS Default VirtualHost
    • Monitoring Globus Connect Server
    • MRDP
    • Require a Flow for Data Movement
    • Use Globus Preview
© 2010- The University of Chicago Legal Privacy Accessibility