Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

User Groups

CTS
eCTS

This section of the admin panel is used to create user groups that will be subject to the role model rules.

⚠️ It is important to correctly create and include users in the group! Otherwise, even a properly configured rule will not work, as it will not be able to determine its scope. Therefore, before checking the rules, ensure the user group is configured correctly.

Creating a User Group

Field Description
Group name It is advisable to specify a unique and descriptive name for the user group.
Platform Web, Desktop, iOS, Android. You can select all at once.
Connection type Select the Corporate Data Transmission Network (CDTN) contour, which is configured in the File Service section:
  • Internal — users within the CDTN contour (IP address is included in the mask list specified in the Contour section);
  • External — users outside the CDTN contour (IP address is not included in the mask list specified in the Contour section).
To ensure CDTN settings do not interfere with the role model, enable Contour in the File Service section (check the Enabled box), set any in all contour rule settings fields, and specify the IP masks of your corporate network.
Corporate device status Indicates whether the user's device is corporate. For this feature to work, corporate certificates must be pre-generated and configured on client devices, along with additional server-side configuration. For details, please contact eXpress support or refer to the administrator documentation.

What Does “Corporate Device Status” Look Like on the User Side?

If the server administrator has enabled corporate status verification and the user's device has not yet been confirmed as corporate, a Confirm corporate device option appears in the app settings. When tapped and confirmed:
  • if a valid corporate certificate is installed on the device — the OS prompts for the private key password and confirmation to use the certificate with the eXpress app; upon success, the user sees a Corporate device role confirmed notification, and the setting item disappears;
  • if there is no certificate or it is invalid — the user sees the message Client certificate is invalid. This device cannot be confirmed as a corporate device;
If a previously confirmed device loses its corporate status (for example, the certificate is revoked, or the same certificate is confirmed on another device), the Confirm corporate device option appears again in settings, and a dot marker is displayed next to the user's avatar — similar to the “Server maintenance in progress” indicator.

Adding Users to a Group

Field Descriptions

Field Description
AD groups
(is a member/not a member)
Search is available only for global Active Directory groups. You can manually enter values for universal groups using Enter. User membership in the group is not yet verified.
User Groups from Active Directory

When creating a user group in Active Directory for a group in the role model, set the Scope parameter to Universal. The Domain Local or Global options are not suitable for use in the role model.

Currently, only universal AD groups are supported. The search field currently only finds global groups, so universal groups must be entered manually and confirmed with Enter.

Currently, you cannot view who is included in the group. There is also no option to select an AD group from a list. This is planned for the future.

Since user membership in an Active Directory group is not currently verified, the easiest way to test a rule is to specify a specific user in the group: search for their login or enter their HUID and press Enter.
OpenID roles
(is a member/not a member)
No search available. You can manually enter values using Enter. User membership in the group is not yet verified.
User Roles from OpenID (Keycloak)

A user's OpenID role, like an AD group, must be specified in the user profile in the admin panel of CTS.

Roles are synchronized from OpenID fields under the Role mapping tab in the Users section of the Keycloak admin console.

If a role is missing from the user's profile in the CTS admin panel:

  1. Perform a standard synchronization by clicking Synchronize in the registration settings.
  2. The affected user must restart their session in the application.
  3. If this does not help, contact eXpress support.
Position No search available. To manually add values, save the group changes. User membership in the group is not yet verified.

These field values are entered manually. They can be copied from the user profile. To save changes, click the Save Group button.
Company
Department
Domain
Specific users Search by login is available. You can manually enter HUID values using Enter. User membership in the group can be verified by the HUID value.
⚠️ The Specific users field can contain no more than 100 users.

To find specific users or excluded users, start typing the login and select the appropriate option from the dropdown, or enter the user's HUID and press Enter.


You can upload user lists from CSV files (using the same format as for the Users section).

Excluded users

How to Create a Group with All Users?

For the rule to apply to all server users, do not select anything: neither an AD group, nor an OpenID role, nor a property, nor a specific user.

How Do AD Group and OpenID Role Selection Work Together?

The filtering works on the principle of logical “AND”: a user will be included in the role model user group only if they have a match in both the AD group and the OpenID role.