---
title: "Managing Groups"
slug: "360023404974-creating-user-groups"
tags: ["Essentials", "Premium", "Enterprise"]
updated: 2026-04-07T09:08:35Z
published: 2026-04-07T09:08:35Z
canonical: "support.perimeter81.com/360023404974-creating-user-groups"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.perimeter81.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing Groups

<meta charset="utf-8">

## Introduction

The Groups page allows you to create groups of members, based on roles and locations. For example, it allows you to apply a Policy to multiple members or restrict access only to a segment of the network.

Note - Segmenting networks uses the Software Defined Perimeter (SDP) technology. This isolates sensitive data and reduces the attack surface, minimizing the impact during security breaches.

To view the Groups page, access the Check Point SASE Administrator Portal and click **Team** > **Groups**.

![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187676247.png)

| Column | Description |
| --- | --- |
| Group | Group name. |
| Networks | Name of the networks assigned to the group. |

## Steps

#### Creating a Group

<meta charset="utf-8">![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/Group_create.gif)

#### <meta charset="utf-8">

1. Access the Check Point SASE Administrator Portal and click **Team** > **Groups**.
2. Click **Add Group**.  
Note:You can search and select users in the **Assign new members** section in the right-pane.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/Assign_new_member(1).png)
3. Enter the group name and click **Create Group**.
4. To add members to the group:
  1. Click![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749186980872.png)in the last column of the group and then select **Manage Members**.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187064777.png)
  2. In the **Assign new members** section, click + and select the required members.
5. To add networks to a group or to grant access to a network segment:
  1. Click![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749186980872.png)in the last column of the group and then select **Manage Networks**.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187088865.png)The **Assign Network to Group** pop-up appears.
  2. Select the network and click **Done**.  
The members can access only the selected networks from the Check Point SASE Agent.
6. To delete a group, hover over the group that you want to delete and click ![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187151847.png).![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187134718.png)The **Delete Group** window appears.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187190850.png)
7. Click **Delete Group**.

Notes:

- A group can also be automatically created as a result of an IDP sync over SCIM, and associate users with it.
- When a group is deleted in the identity provider (example: Okta), it remains in any policies or configurations where it was previously used. It appears greyed out, and when you hover over it, **Deleted Group**message is displayed.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1749187404669.png)
- You cannot add the deleted group in any policies, but it can be removed from the existing policies.
- When the deleted group is re-enabled, it is restored without any members. To add members again, you must manually assign them through the IdP.

#### Editing members in a group

1. Once you have created a Group, you can edit members by selecting the three-dotted menu (...) on the right side and choosing **Manage Members**.  
![360008598400managemembersmenuoption.png](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/360008598400managemembersmenuoption.png)
2. Select the + sign to list members. Select the team members you want to add to the Group. Please notice that you will see only non-members on the list.  
![360008599719assignnewmembers.png](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/360008599719assignnewmembers.png)  
The new members are added to the group.

#### Managing access for groups

1. Groups are created to control who can access which location. Select **Groups** in the left side panel.
2. Select the three-dotted menu (...) next to the group you’d like to limit or grant access to and select **Manage** **Networks**.

1. Select or remove the teams as desired for this location.

![360007723319assignnetworktodialog1.png](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/360007723319assignnetworktodialog1.png)

## Support Contacts

If you have any difficulties or questions, don't hesitate to contact Check Point SASE's support team. We offer 24/7 chat support on our website at [sase.checkpoint.com](https://www.sase.checkpoint.com/), or you can email us at sase-support@checkpoint.com. We're here to assist you and ensure your VPN tunnel setup is a success.
