Concept and mechanism
Individual accounts and login classes separate identity from privileges. For operational inspection, choose permissions matching the work instead of supplying superuser with a verbal instruction not to edit. Configuration groups add reuse: apply-groups inherits settings at hierarchy points. Absence of an explicit line in an interface block does not prove absence of the effective value; display inheritance helps observe origin and result. Interface hierarchy matters too. Unit identifies a logical interface and family inet selects IPv4; the unit number is not a universal guarantee of equivalence to VLAN ID.
Guided application
In a fictional case, a small shared-group edit changes several interfaces outside the ticket. Before editing each consumer, identify where the group applies and compare inheritance. If the window cannot accommodate a safe correction, revert known scope and prepare a more bounded change. Also retain a valid rescue configuration representing recoverable state. Loading rollback rescue changes the candidate; review the result and commit to activate. An old rescue may not match current dependencies, so it needs review after relevant changes. At handover, record who may use it, how to obtain authorized access, and which checks demonstrate recovery. Do not confuse file existence with a rehearsed recovery procedure.
A group applied to ten interfaces can widen one edit impact.
Common pitfalls
Shared account as traceability; explicit configuration as all configuration; unit as universal VLAN; loaded rescue as active.
Related topics: Addressing and capacity · Junos planes and state interpretation · CLI, candidate, and rollback
Review permissions, inheritance, and recovery as part of change.
Reference: Configuration group inheritance · JN0-106, effective 2026-04-06; Junos OS 21.2 exam baseline