<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Custom Admin Role Receives "You Don't Have Permission to Edit This Group" Despite Group Being in Resource Set

Okta Identity Engine
Directories

Overview

A custom administrator with group management permissions encounters an error when attempting to manage membership in a group included in the resource set. This occurs because the group is assigned to an application or used to grant an administrator role. To resolve this, add the application to the resource set and grant application assignment permissions, or use a Super Administrator account to manage the group.

 

You don't have permission to edit this group

 

Applies To

  • Okta Identity Engine (OIE)
  • Custom Administrator Roles
  • Resource Sets
  • Groups

Cause

This issue occurs for two reasons. 

First, the group is assigned to an application. When a group acts as an application assignment group, editing its membership indirectly controls application access. Okta requires the "Edit application's user assignments" permission and the inclusion of the relevant application in the resource set to manage these groups.

 

Second, the group grants an administrator role. Okta protects groups bound to administrator role assignments from modification by custom administrator roles, preventing privilege escalation. This restriction applies regardless of the resource set configuration and cannot be overridden by a custom role.

Solution

How is the application assignment scenario resolved?

Edit the custom administrator role to include application assignment permissions and add the application to the resource set.

  1. Navigate to Security > Administrators and open the custom administrator role assignment.
  2. Edit the role to include the Edit application's user assignments permission under Application permissions.
  3. Add the application that the group is assigned to in the resource set.
  4. Save the changes.

 

A Super Administrator must manage groups used to assign an administrator role.

Custom administrator roles cannot manage groups bound to administrator role assignments. A Super Administrator must perform the operation directly, or a Super Administrator must remove the group from the administrator role assignment before the custom administrator can manage it.

 

NOTE: If it is unclear whether a group falls into one of the above categories, a Super Administrator can check by navigating to the group in the Admin Console and reviewing the Applications tab and Administrators tab.

Loading
Okta Support - Okta Custom Admin Role Receives "You Don't Have Permission to Edit This Group" Despite Group Being in Resource Set