Up until recently, our Cloud instance was open (to logged-in users). We want to keep our information transparent, and many of our users work in multiple projects.
However, we recently added a team that's part of the organization, but kind of standalone, and we do not want them to be able to see our other projects.
I'm planning on updating our default permission scheme to use a project role for Browse Projects, but don't want to have to update 40+ separate projects with individual users. Ideally, those 40+ projects would have a project role containing a group that in turn contains all users except the new team.
Therein lies the issue: we have almost 500 users in our default access group. What I now need to do is create a copy of that group with 475 users. It would be much easier if I could create a copy of our default group and then just remove the users in question, but I'm not aware of a way to do that. I'm happy to work with the REST API if necessary, since this is going to be a one-off. I'm also happy to temporarily install an add-on if there's one available that will do this.
Any ideas?