Add and Remove Okta Users From Groups Using Group Rules and Exceptions
Last Updated:
Overview
Administrators can automate group memberships and application assignments by configuring Okta group rules based on user attributes. When an administrator manually removes a user from a rule-managed group, Okta automatically adds the user to the rule exception list to prevent re-addition. Modifying the user attribute removes the user from the group without adding them to the exception list.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Groups
- User Attributes
- Group Rules
- User Lifecycle Management
Solution
How do Okta group rules evaluate user attributes?
Create group rules that pull information from user attributes, such as the department attribute, to place users in the proper groups for their job category. This automatically changes the application set of the user if they transfer to a different department. For example, a Sales group contains Salesforce, Workday, and ADP, while a Finance group contains Salesforce, eTrade, and Fidelity. Designate an attribute to parse a group rule to assign users to these groups.
Review the following example of a group rule configured to evaluate the department attribute for the Sales value.
When activated, the group rule evaluates the Universal Directory (UD) for users with the Sales value in their department attribute. If the attribute matches, Okta adds the user to the Sales group.
What happens when a user is manually removed from a group?
If an administrator manually removes a user from the Sales group, Okta automatically adds the user to the EXCEPT The following users field in the group rule. This allows the group rule to continue running on any new users with the Sales value in the department attribute without erroneously re-adding any manually removed users.
If the attribute of the user changes to Finance, Okta removes the user from the Sales group but does not add the user to the list of exceptions. If the department attribute reverts to Sales, the group rule reapplies, and Okta re-adds the user to the group.
The Manage People button does not add users to the exception list.
NOTE: Using the Manage People button in the group does not add users to the rule under the EXCEPT The following users field. Using this button adds the users to the Members and Not Members lists.
Review the following examples of the group management interface displaying the Members and Not Members lists.
