Guides
  • Guides
  • Tutorials
    • File Management
    • Manage Identities
    • Storage Connectors
    • Automation with Flows
  • Overviews & Concepts
    • Clients, Scopes, and Consents
    • Collections and Endpoints
    • High Assurance Collections for Protected Data
    • Security Overview
  • Recipes & Manuals
    • Automating Transfer and Share of Data from Instruments
    • Automation with Service Accounts
    • GCS Apache Reverse Proxy
    • GCS Default VirtualHost
    • Monitoring Globus Connect Server
    • MRDP
    • Require Flow on Collection Transfer Actions
    • Use Globus Preview
Skip to main content
Globus Docs
  • APIs
    Auth Flows Groups Search Timers Transfer Globus Connect Server Compute Helper Pages
  • Applications
    Globus Connect Personal Globus Connect Server Premium Storage Connectors Compute Command Line Interface Python SDK JavaScript SDK
  • Guides
  • Support
    FAQs Mailing Lists Contact Us Check Support Tickets
  1. Home
  2. Guides
  3. Tutorials
  4. Manage Identities
  5. Mark a Group as High-Assurance

Designate a high-assurance group for use with restricted data

When managing access to restricted data in guest collections, permissions may assign access to groups as well as to individuals. Each group must be flagged as a high-assurance group.

To designate a high-assurance group, locate the group in the Groups section of the Globus Web App. If the group isn’t listed on the main page, search for it by name.

Search for a group

Once you’ve located the group, click the group’s name to view its configuration, then click "Settings" to open the Settings tab. In the "Policies" section, click "Edit Policies."

Edit the group's policies

Near the end of the list of policies, find "Session enforcement for this group is." The two options are "not strict" (the default) and "strict." Change the policy to "strict" to designate that this is a high-assurance group. Change the authentication duration (defaults to 28800 seconds, or eight hours) to the value required by your institution. Click "Submit."

Set strict session enforcement

At this point, your group is now designated for high-assurance use.

When you return to the group settings page, you may see a notice that you must authenticate as a specific identity to make further changes to the group. Because the group is now using strict authentication, this is expected if you haven’t authenticated to the required identity in the current session. Follow the prompts to re-authenticate.

Required identity
  • Guides
  • Tutorials
    • File Management
    • Manage Identities
    • Storage Connectors
    • Automation with Flows
  • Overviews & Concepts
    • Clients, Scopes, and Consents
    • Collections and Endpoints
    • High Assurance Collections for Protected Data
    • Security Overview
  • Recipes & Manuals
    • Automating Transfer and Share of Data from Instruments
    • Automation with Service Accounts
    • GCS Apache Reverse Proxy
    • GCS Default VirtualHost
    • Monitoring Globus Connect Server
    • MRDP
    • Require Flow on Collection Transfer Actions
    • Use Globus Preview
© 2010-2025 The University of Chicago Legal Privacy Accessibility