---
title: User Group Definition Tab
slug: kronpam-reference-guide-3-5-0/user-group-definition-tab
description: Learn about the User Group Definition tab in our User Management document. Discover how the various checkboxes like Password TTL, Autonomous Group, and Admin Group enable seamless management and customization of user groups. Maximize efficiency with featu
docTags: 
createdAt: 2022-08-03T10:11:40.000Z
---

The **User Group** is under the **User Menu**. User Groups can be created, edited, and deleted from this page. User Group features are addressed in this section.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/s3JseoVecqKjEdE6uLjSv_image.png" size="58" width="654" height="640" position="center" caption="User Group Definition features" showCaption="true"}

**Password TTL (Days):** Defines
the maximum time allowed for the use of passwords for users in the configured user group. When a user's password reaches its TTL, they are forced to change it the next time they log in. Setting this feature as **-1** means that the password of the users in this group will never expire. If this value is set to **0** (zero) or left empty, the user group, and consequently the users, will be ignored during the password expiration control.

**Autonomous Group**: This checkbox defines the autonomous users’ group (e.g., script users). This group’s users may be excluded from RADIUS logs to avoid creating a log flood. These users’ passwords never expire.

**Direct Access**: When Kron PAM is configured as a AAA or TACACS+ server for devices with AAA with TACACS+ protocol, the **Direct Access&#x20;**&#x63;heckbox needs to be checked. All connections should go through Kron PAM.

**Console Access**: Similar to the **Direct Access** permission, this checkbox gives the AAA and TACACS+ devices console access.

**Admin Group**: This checkbox gives admin rights to all users belonging to that user group.
