Okta Custom Admin Roles Cannot Grant Administrator Privileges
Last Updated:
Overview
Okta restricts administrator assignment changes to the Super Administrator role because custom administrator roles do not include permissions to add or remove other administrators. Use a Super Administrator to grant administrator privileges, and use the existing feature request if this capability is needed in a custom role.
The issue appears when an administrator attempts to create or use a custom role to grant administrator permissions to another user or service account.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Administrator Roles
- Custom Roles
- Security
Cause
Okta allows only the Super Administrator standard role to add or remove other administrators. Custom administrator roles do not include the permissions required to manage administrator accounts or role assignments.
Solution
How is administrator privilege assignment completed?
Use a Super Administrator role to add or remove administrator privileges. Review the supported permissions in Standard administrator roles and permissions. This feature was requested on the Okta Ideas page, but the current status is: Not at this time because it does not fit into Okta's current product strategy.
Related References
