The Default group
In this topic, you will learn what is the Default group, how it differs from other groups, and how it functions in Portnox Cloud.
The Default group is a catch-all group that always exists in Portnox Cloud. All devices and users that fail to authenticate or are not explicitly assigned to a custom group are automatically placed here. Membership cannot be manually managed, and external repository mapping is not supported.
Usage and limitations
You cannot assign OUs, accounts, or groups manually to the Default group.
External identity platforms (Entra ID, Google Workspace, Okta, LDAP) cannot be mapped to the Default group.
It is recommended to enable both wired and wireless access in the Default group and assign policies or VLAN/ACLs appropriately. This ensures fallback connectivity for unassigned devices or failed authentications.
Custom groups should be used for targeted access control, directory integration, and policy enforcement.
The Default group is fixed at the bottom of the priority list and cannot be moved. Custom groups can be rearranged above it to control policy application.
