Set Up Group Sharing for Drive
- Security:Drive Administratordomain in the System functional area.
- For each security group that you want to share items with, make sure that the group is in both:
- The Drive domain.
- The domain for the item type you want to share. For example, if you want to share Worksheets workbooks with a security group, the security group must have access permissions for the Worksheets domain.
You can let self-service users share items of specific types with one or more security groups. A user can share items of that type with the group, even if the user who shares the item isn't a member of the group.
If you decide not to configure group sharing, the option won't display in the Share dialog. Drive will continue to allow only sharing with individuals, and sharing using a link/URL.
The table below identifies item types and the security groups you can share with. Keep in mind that although Drive itself doesn't allow sharing with constrained security groups, some Drive application integrations do allow constrained group sharing. If that's the case, the group displays in the selectable list of security groups. Example: Worksheets doesn't allow sharing with constrained security groups, but some applications that integrate Worksheets into their workflow do allow it.
You can configure:
- Role-based groups if they meet the restrictions defined in the table.
- Public groups for all item types except document templates and notification templates, if they meet the restrictions defined in the table.
Drive doesn't support group sharing with Intersection Security Groups.
Item Type | Security Group |
|---|---|
Discovery Board | Any security group in the system. To share with View permission, the group must have access to at least 1 data source used in the board. To share with Edit permission, the group must have Modify access to the Discovery Board: Create domain. |
Document Template | Any unconstrained group added to the security policy for the Docs domain. |
File | Any unconstrained group added to the security policy for the Drive domain. |
Folder | Any unconstrained group added to the security policy for the Drive domain. |
Media | Any unconstrained group added to the security policy for the Drive domain. |
Notification Template | Any unconstrained group added to the security policy for the Notification Designer domain. |
Presentation | Any unconstrained group added to the security policy for the Slides domain. |
Workbook | Any unconstrained group added to the security policy for the Worksheets domain. |
Configuration considerations:
- Educate your self-service users on when group sharing is appropriate.
- When configuring groups for group sharing, make sure all the group members know about their own membership in the group, and they're familiar with who else is in the group.
- If you're creating security groups to configure for group sharing, give them meaningful names that are understandable by self-service users.
- If you used a large group like All Workers to grant access to an application, consider adding smaller groups to meet your needs for group sharing use cases. Example: Instead of selecting to enable group sharing for the All Workers security group, you might want to limit it to the Recruiters group.
- Access theConfigure Group Sharing in Drivetask.
- (Optional) Select theOnly Admins Can Group Sharecheck box.When selected, the configuration that you set up in the rest of these steps will apply only to Drive administrators; group sharing search won't be visible to self-service users.If you limit group sharing to administrators, then:
- Only Drive administrators who have Edit access or higher to a Drive item can share that item with a security group.
- Self-service users won't see theShare with Groupoption in the Share dialog.
- Self-service users can be the recipients of group shared items, and they can see which items were shared with them as part of a group, but they can't modify or remove their sharing permissions.
- Add each item type that you want to be sharable with a security group, then select which security groups the items can be shared with.By default, after you select the item type, all security groups with access permission for that item type automatically display. Delete any security groups that you don't want users to share with.The File item type is associated with any file type that doesn't fall into a more specialized category in Drive; in other words, these are the file types that you enable in Workday using theEdit Tenant Setup - Systemtask, in theFile Type Setup Instructionssection. When you enable group sharing for the File item type, you're enabling group sharing for all of these file types.For the Folder item type, if you enable group sharing and then a user shares a folder with a group, the permissions propagate to the files in the folder whether or not the individual file's type was enabled for group sharing. Example: Media files in a shared folder inherit permissions based on the shared folder's setting, even if the media file type isn't specifically enabled for group sharing.
Self-service users see these changes in the user interface after you enable group sharing, if you didn't limit it to administrators:
- Any Drive user will see theShare with Groupssection of theSharedialog when they choose to share a Drive item.
- Drive users can start typing a group name into theShare with Groupsfield to see which groups they can share with.
- Drive users can view and manage what groups have access (and the level of access) to a group-shared item in theWho Has Accesstab of theSharedialog.
- When a user gains or loses membership to a group, they automatically gain or lose access to items that someone shared with that group.
- Unlike sharing with individual users, when you share an item with a group, Workday doesn't send notifications. You might want to notify people that you shared an item with them. Example: If you shared a Worksheets workbook with a group, you can send then an email containing a link.