This article explains the limitations of a Group Admin that can manage only certain groups in the organization.
- Okta groups
- Admin Roles
- Okta Classic Engine
Group Admin has the following permissions for making changes to groups in Okta:
A Group Admin can be allowed to administer either all users or only users in specific groups.
- NOTE: If the admin should have access to all Groups, Constrain this role to the entire organization setting should be checked.
- In the screenshot below, the Group Admin is set to administer only the users in the Okta Group named Group 1.
- When access is limited to some groups, Group Admins can create a new user and assign the managed group to that user but cannot assign existing users to the group.
- NOTE: Permissions apply only to groups that the admin is allowed to manage.
