<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Admin Erroneously Receives "Super Org Admin Privilege Has Been Revoked" Email
Administration
Okta Classic Engine
Okta Identity Engine
Overview

This article explains why an administrator receives an email notification indicating their privileges were revoked when no revocation occurred. The email contains the following subject line:

 

Your Super Org Admin Privilege Has Been Revoked

 

Applies To
  • Administrators

Cause

This email notification is triggered by a feature introduced in release 2020.05.0. The feature revokes admin privileges when a user with an admin role is deactivated. The deactivated user is then removed from the Administrators page and from the Comma-Separated Values (CSV) download list of administrators.

 

Deactivated admin users: When a user who has an admin role and privileges assigned to them is deactivated, their admin privileges are revoked. The deactivated user is removed from the Administrators page and from the CSV download list of administrators.

 

NOTE: If an active administrator shares an email address with a deactivated user account, the active administrator incorrectly receives the revocation notification.

Solution

The email notification is expected behavior based on the feature enhancement. To identify the deactivated user that triggered the notification:

  1. Go to Reports > System Log.

  2. In the search bar, enter the following query:

    eventType eq "user.account.privilege.revoke"
    
  3. Review the logs to verify which user account was deactivated.

Loading
Admin Erroneously Receives "Super Org Admin Privilege Has Been Revoked" Email