Device groups
Groups bundle devices so you can target tunnels, access rules, and operations consistently.
When to use groups
- Apply the same tunnel access or provisioning defaults to a fleet.
- Organize devices by team, site, or environment.
- Prepare for access control policies configured on the group (see the guide on protecting a group).
Create a group
- Open Infrastructure → Device groups.
- Choose Create group.
- On the General tab, set name and description and pick a color if your team uses colors for quick recognition.
- Confirm which organization owns the group.
- Save.
Add devices to a group
- From the group list, use the actions available for your role to assign devices or open the device list for the group.
- From Devices, you can often move a device into a group when editing device details (depending on your permissions).
Migrate a group (optional)
If your tenant hierarchy allows it, you may see an option to migrate a group to another organization. Use this when restructuring teams; migration moves the group and its devices together. Follow any confirmation steps shown in the dialog.
Tips
- Keep group names short but meaningful (
NYC-warehouse,Lab-test). - Prefer a small number of well-named groups over many overlapping ones.
