<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta SystemPrincipal Adds a User to a Group Exclusion List

Lifecycle Management
Administration
Okta Classic Engine
Okta Identity Engine

Overview

When an administrator manually removes a user from a group that a group rule manages, Okta automatically adds the user to the group rule exclusion list. This expected behavior prevents the group rule from re-adding the user during the next evaluation. Administrators can review these automated actions in the System Log and manage the exclusion list in the Okta Admin Console.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Groups
  • Group Rules
  • User Lifecycle Management

Solution

Why does Okta add a user to a group rule exclusion list?

If an administrator manually removes a rule-managed user from a group via the Okta Admin Console or the Group API, Okta automatically adds that user to the Except The following users field for that rule. This ensures the group rule respects the manual removal and does not re-add the user during the next evaluation.

 

How are group rule exclusions verified in the System Log?

Review the System Log to verify the automated exclusion and the manual removal events.

  1. The user profile displays the group membership assigned by the rule.
    Group membership removed from User profile page
  2. An administrator selects the X icon to remove the user from the group.
  3. Okta records two separate events in the System Log. The group.user_membership.rule.add_exclusion event indicates the automated action by SystemPrincipal, and the group.user_membership.remove event indicates the manual removal by the administrator.
    2 System Log Events

 

How do administrators view the group rule exclusion list?

Navigate to the group rules in the Okta Admin Console to view or manage the exclusion list.

  1. Navigate to Directory > Groups in the Okta Admin Console.
  2. Select the Rules tab.
  3. Search for the specific rule in the list.
  4. Select Actions and choose View to see the added exception.
    Group Rule A Exclusion

 

NOTE: Okta allows a maximum of 100 users in a group rule exclusion list. If the Okta SystemPrincipal action adds more than 100 users to the exclusion list and an administrator deactivates the rule, Okta prevents reactivation until the exclusion list contains 100 users or fewer. Evaluate the group rule expression for improvements to avoid requiring excessive exceptions.

 

Related References

Loading
Okta SystemPrincipal Adds a User to a Group Exclusion List | Okta Support