---
title: Device Groups Properties
slug: kronpam-reference-guide-3-5-0/device-groups-properties
description: This SEO description provides an overview of the document's content on various properties for Device Groups in Kron PAM. It includes options for SSH keys, usernames, and passwords, managerial approval, common passwords, global credentials, notifications, 
docTags: 
createdAt: 2022-08-01T12:07:00.000Z
---

Some Kron PAM features are managed via Device Groups. The features are activated by defining the device group properties.

To set the property for Device Group:

&#x20;      1\.	Navigate to **Devices > Inventory**
&#x20;      2\.	Click on the **+Add** button and select the  **Add Group&#x20;**&#x6F;ption.
&#x20;      3\.	Fill out the **Device Group Name** and description fields and click **Next.**
&#x20;      4\.   Set the preferred properties. (i.e. Direct Credential, Additional Credentials, or Custom Properties.)

| **Property Key**                         | **Definition**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **addDeviceSshKeyToUserSelection**       | This property only applies to devices imported from AWS (Amazon Web Services).&#xD;<br />If the value is set as **true**, connecting to devices with an SSH key is offered as a connection option.&#xD;<br />This property can be used when the following conditions are set:<br />1) The **sshKeyName** and the **sshUsername** property keys should be defined in the device properties for preferred devices.
2) The SSH Private Key corresponding to the **sshKeyName&#x20;**&#x69;n the device property should be defined in the SAPM. |
| **addManualLoginToUserSelection**        | This property applies to SSH/TELNET and RDP/VNC proxies in the Session Manager module. The default value is **false**. When the value is set as **true**, the user can manually enter the device username and password at the start of the session.                                                                                                                                                                                                                                                                                         |
| **addSessionUserToUserSelection**        | This property only applies to SSH/TELNET and RDP/VNC proxies in the Session Manager module. When the **addSessionUserToUserSelection** property is set as **true&#x20;**&#x6F;n a device group, users can connect to target devices in the device group using their username to log in to Kron PAM.                                                                                                                                                                                                                                         |
| **approvalRequiredForConnection**        | This property only applies to SSH and RDP proxies in the Session Manager module. When its value is set as **true**, managerial approval is requested via email for users to connect to devices in the device group.                                                                                                                                                                                                                                                                                                                         |
| **globalEnablePassword**                 | This property only applies to the TACACS+ Access Manager module. Bot/script users need to use a common password to switch to **enable mode** in scripts.  The **globalEnablePassword** property allows the definition of<br />a common password for a device group, to be used when the enabled password is prompted.                                                                                                                                                                                                                       |
| **globalPassword**                       | It is the password of the globalUsername. The password is to be used when connecting to all devices covered by the device group.                                                                                                                                                                                                                                                                                                                                                                                                            |
| **globalSecretKey**                      | This property only applies to the TACACS+ Access Manager module. The secret key to be used when authenticating all devices covered by the device group to TACACS+<br />servers. It is a mandatory property when using the TACACS+ Access Manager.                                                                                                                                                                                                                                                                                           |
| **globalSshKey**                         | This property only applies to SSH proxies in the Session Manager module. If connecting to the device with an SSH Key is preferred, **globalSshKey**<br />should be defined for the Device Group.                                                                                                                                                                                                                                                                                                                                            |
| **globalSshKeyPassphrase**               | This property only applies to SSH proxies in the Session Manager module. If the device to be connected to has an SSH passphrase, **globalSshKeyPassphrase&#x20;**&#x73;hould be defined for the Device Group.                                                                                                                                                                                                                                                                                                                               |
| **globalUsername**                       | The username is to be used when connecting to all devices covered by the device group. This username must be pre-defined as a user on all devices in the device group.                                                                                                                                                                                                                                                                                                                                                                      |
| **sapmMailList**                         | The sapmMailList is notified when the following situations occur in SAPM:<br />• When a user retrieves a password for an SAPM account included in the device group.<br />• If an error occurs during the password reset of an SAPM account included in the device<br />group.<br />• If the password cannot be verified while checking the password of an SAPM account included in the device group.<br />• If a new user is detected on a device that has an SAPM account<br />included in the device group                                |
| **sessionPlayAlertMailAddresses**        | Users can enter one or more email addresses separated by commas in this parameter to specify where the alert notifications when someone views a "Play Session" in the "Session Logs should be sent.                                                                                                                                                                                                                                                                                                                                         |
| **showInDeviceTree**                     | This property is used along with the **useAsRoleGroup&#x20;**&#x70;roperty. When its value is set as **false**, the device group cannot be seen in the<br />device inventory screen. Once devices are authorized with the main device group, this property can be set for the device group. After that, users cannot<br />see this device group in their device inventory. Users with the same authorization level as the device group, defined by the group role, can still only see the other device groups.                              |
| **tag.DiscoverInterfaceType**            | When importing devices from cloud platforms, the Management IP is set according to the values of the defined property.<br />Possible values are **public** and **private**. The default value is **private**.                                                                                                                                                                                                                                                                                                                               |
| **useAsRoleGroup**                       | Some devices can be defined in multiple device groups. In this situation, device authorization can<br />be defined in one device group. The **useAsRoleGroup** device group property value must be set as **true** for the device group in which authorizations are<br />managed with policy enforcement, such as the black key/white key.                                                                                                                                                                                                  |
| **useSudoForLinuxAuditReport**           | This property only applies to the Linux Audit Report feature. The default value is **false**. If the globalusername defined on the Device Group is sudo user and the **sudo** command execution is required to get report details, the property must be defined as **true** on the Device Group.                                                                                                                                                                                                                                            |
| **addAssignedCredentialToUserSelection** | The default value is **false**. When the value is set as **true,** the users can use their assigned credentials in the target device. For more details, please refer to chapter [Assigned Credentials](docId\:zgITeDt9mSGTVMrtYiZZ_)                                                                                                                                                                                                                                                                                                        |
| **sessionDurationLimitMinute**           | User session duration can be limited.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **reasonRequiredForConnection**          | When the value is set as **true**, a comment/reason<br />field appears when users try to connect to the devices in the device group. The text entered here will appear in the session logs, managerial approval emails, and notifications (if enabled).                                                                                                                                                                                                                                                                                     |
| **skipRdpAuthOnAutoDiscovery**           | When the value is set as **true** on the device group KronPAM will not try to send SMB messages to a server. If a network is successful, a device will be added.                                                                                                                                                                                                                                                                                                                                                                            |

