17.3 The Difference Between Group Types

Key Takeaways

  • Account groups are target-system groups, aggregated as ManagedAttributes in the Entitlement Catalog and certified in account group certifications.

  • Workgroups are sets of identities (stored as Identity objects) that share ownership, work items, and IdentityIQ capabilities and scopes.

  • Groups are generated by a Group Factory from one Group Factory identity attribute, one GroupDefinition per value, for filtering and statistics.

  • Populations are saved Advanced Analytics queries on searchable attributes, stored as GroupDefinition objects and re-evaluated each time they are used.

  • Populations can be used in IT role mining and Activity Search, but groups cannot.

Last updated: September 2026

The Difference Between Group Types

Objective 7.7 asks you to understand the difference between different group types. In IdentityIQ, "group" can mean four different things, plus roles, which also group access. The exam checks that you pick the right one.

The Four "Groups" at a Glance

TypeWhat it groupsHow it is createdStored asMain purpose
Account group (application object)Accounts on a target application, such as an AD groupAccount Group Aggregation from a group schemaManagedAttribute (group entitlements)Entitlements: catalog, requests, account group membership and permissions certifications
WorkgroupIdentityIQ identities who share responsibilitiesSetup > Groups > Workgroups (Create Workgroup)An Identity flagged as a workgroupShared ownership, work items, approvals, certifications, and capabilities and scopes
Group (Group Factory group)Identities that share one value of one identity attributeSetup > Groups > Groups, Create New Group on a Group Factory attributeGroupFactory, a GroupDefinition per value, and a GroupIndex (scorecard)Filtering tasks, certifications, and reports, plus statistics such as members, violations, and risk
PopulationIdentities matching a multi-criteria queryAdvanced Analytics: save identities as a populationGroupDefinitionFiltering and targeting: certifications, tasks, reports, QuickLink populations, role mining, Rapid Setup

Roles (Bundles) are different again. They model job functions and entitlements, affect provisioning, and appear in certifications (section 16.1).

Account Groups

Account groups exist on the target system. IdentityIQ reads them with Account Group Aggregation (section 13.1), and all groups read are added to the Entitlement Catalog as managed attributes. Account groups:

  • can be requestable, owned, described, and classified.
  • are certified in Account Group Membership certifications (the right accounts in the group) and Account Group Permissions certifications (the right permissions on the group). Groups without owners are certified by the application owner.
  • are linked to accounts through the account schema's entitlement attribute type (section 12.2).

Workgroups

A workgroup lets several people act as one owner. Assign a workgroup as an application owner, certifier, approver, policy violation owner, or work item owner, and any member can act. Workgroups also carry Capabilities and Authorized Scopes, which members inherit. For example, a "Certification Admins" workgroup can hold the Certification Administrator capability.

Workgroup settings include an owner, description, a scope that limits who can see the workgroup in selection lists, a Group Email (ideally a distribution list), and Notification Setting:

  • Notify members and group email (members may receive two copies if the group email is a distribution list)
  • Notify group email only
  • Notify members only
  • Disable notifications

Groups (Group Factories)

  • Only identity attributes flagged Group Factory (section 16.3) can define groups.
  • Creating a group on, say, Region produces one GroupDefinition per value, for example North America, Western Europe, and Asia. You create sets of groups, not single groups.
  • Membership is evaluated when the group is used, by filter. The list of GroupDefinitions and the GroupIndex statistics are updated only when Identity Refresh runs with Refresh the group scorecards. A new attribute value gets no group until that refresh runs. The Refresh Groups task and console refreshGroups / refreshFactories also maintain them.
  • Groups can also be based on common entitlements through the role group attribute. Identities matching no role fall into a No role group, and a Global group contains everyone.

Populations

  • Built in Advanced Analytics from Identity Search or Advanced Search. They can combine multiple criteria on searchable attributes, with AND/OR and operators beyond equals.
  • The query is saved, not the member list. Membership is re-evaluated at each use.
  • They are also stored as GroupDefinition objects, so they can be exported, edited, and reimported as deployment artifacts through the Debug pages or the console.

Where Groups and Populations Can Be Used

UsePopulationGroup
Identity Refresh and Policy Scan task filtersYesYes
Advanced certificationsYesYes
Targeted certifications ("who to certify")YesNot listed (use attribute filters)
Access Review Search criteriaYesYes
Activity Search criteriaYesNo
Report filters (such as Advanced Access Review, Identity Effective Access, Identity Risk, Identity Role)YesYes
IT role miningYesNo
QuickLink populations, lifecycle events, and Rapid Setup filters (selectors)YesNot directly

Exam Traps

  • "Assign the Help Desk capability to everyone in the Help Desk group." If this means people in IdentityIQ, use a workgroup. An AD group is an account group and grants no IdentityIQ rights.
  • "Certify who is in the VPN-Users AD group." That is an Account Group Membership certification, not a workgroup review.
  • "Run a refresh only for EMEA employees in Finance with high risk." That is a population (multi-criteria), not a group (single attribute).
  • "A new region value appeared yesterday, but no group exists for it." Run Identity Refresh with Refresh the group scorecards.
Test Your Knowledge

The service desk team should share ownership of several applications and all receive the same IdentityIQ capabilities. Which grouping should be used?

A

A workgroup, which can own objects and carry capabilities and scopes for its members

B

An account group aggregated from Active Directory

C

A Group Factory on the department attribute

D

A population saved from Advanced Analytics

Test Your Knowledge

A security team wants a reusable set of identities defined as "Finance department AND composite risk score above 700 AND not a manager." What should be created?

A

A Group Factory on the department attribute

B

A population saved from an Advanced Analytics identity search

C

A workgroup with those identities added manually

D

An account group in the Entitlement Catalog

Test Your Knowledge

A Group Factory on the Region attribute exists. A new region value, "LATAM," appears in HR data, but no LATAM group shows up. What makes it appear?

A

Re-saving the Group Factory attribute as searchable

B

Running Account Group Aggregation

C

Creating a new population

D

Running Identity Refresh with the Refresh the group scorecards option (or the Refresh Groups task)

Test Your Knowledge

Which statement about populations and groups in IdentityIQ is correct?

A

Groups store a fixed member list captured when they are saved.

B

Populations can be used for IT role mining and Activity Search criteria, but groups cannot.

C

Populations can only be based on one identity attribute.

D

Groups are created in Advanced Analytics.

Sections you finish are checked off in the contents.

Congratulations!

You've completed this section

Continue exploring other exams