<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Limitations of a Group Admin Allowed to Managed Only Certain Groups
Administration
Okta Classic Engine
Okta Identity Engine
Overview

This article explains the limitations of a Group Admin that can manage only certain groups in the organization.

Applies To
  • Okta groups
  • Admin Roles
  • Okta Classic Engine
Solution

Group Admin has the following permissions for making changes to groups in Okta:

Group Admin permissions   


A Group Admin can be allowed to administer either all users or only users in specific groups.

  • NOTE: If the admin should have access to all Groups, Constrain this role to the entire organization setting should be checked.
  • In the screenshot below, the Group Admin is set to administer only the users in the Okta Group named Group 1.

 Edit Resources to a standard role  

  • When access is limited to some groups, Group Admins can create a new user and assign the managed group to that user but cannot assign existing users to the group.
    Groups assigned  

 

  • NOTE: Permissions apply only to groups that the admin is allowed to manage. 

 

Related References

Loading
Limitations of a Group Admin Allowed to Managed Only Certain Groups