Jeff Huston 

push groups 403 - Access denied - insufficient permission

I have a push group for Box in which I added a member to it in AD. Okta picks up the change but then when it tries to update the group membership I get error "Unable to update Group Push mapping target App group 'group name': Could not add user to specified groups. 403 - Access denied - insufficient permission"

Any ideas? 
Darron Hellmann (Okta)
It sounds as though the user account being used for the Okta Box API doesn't have the necessary permissions to add users to groups.
Jeff Huston
That was my thought too but i am a super admin in Okta and Box so I'm not sure. I know the adminthat set these up has the same permissions as myself in Okta and less in Box. 
Achim Oswald
I have the same issue for one single group, all other groups work. I'm working together with Okta Support and will post as soon as I got it resolved.
Jeff Huston
I ended up figuring this one out, not sure if you have the same issue as me. Box admins/co-admins can’t be in push groups as their group membership can’t be set/ altered by another admin. It was verified by Box. I pulled them out of the push groups and the groups sync fine now. Hope that helps!