when you set the attribute, it should define the type of group principals used in the policy mapping. you can check the policy file for your app under domains/*/generated/policy/<app-name/<module-name>/granted.policy to see if the grants were made in terms of the principal type you configured.
In order for this tow work, you will also need to configure a realm that represents user group membership, by returning principals of your configured type.
Ron
[Message sent by forum member 'monzillo' (monzillo)]
http://forums.java.net/jive/thread.jspa?messageID=301579