Okta Custom Admin Role Receives "You Don't Have Permission to Edit This Group" Despite Group Being in Resource Set
Last Updated:
Overview
A custom administrator with group management permissions encounters an error when attempting to manage membership in a group included in the resource set. This occurs because the group is assigned to an application or used to grant an administrator role. To resolve this, add the application to the resource set and grant application assignment permissions, or use a Super Administrator account to manage the group.
You don't have permission to edit this group
Applies To
- Okta Identity Engine (OIE)
- Custom Administrator Roles
- Resource Sets
- Groups
Cause
This issue occurs for two reasons.
First, the group is assigned to an application. When a group acts as an application assignment group, editing its membership indirectly controls application access. Okta requires the "Edit application's user assignments" permission and the inclusion of the relevant application in the resource set to manage these groups.
Second, the group grants an administrator role. Okta protects groups bound to administrator role assignments from modification by custom administrator roles, preventing privilege escalation. This restriction applies regardless of the resource set configuration and cannot be overridden by a custom role.
Solution
How is the application assignment scenario resolved?
Edit the custom administrator role to include application assignment permissions and add the application to the resource set.
- Navigate to Security > Administrators and open the custom administrator role assignment.
- Edit the role to include the Edit application's user assignments permission under Application permissions.
- Add the application that the group is assigned to in the resource set.
- Save the changes.
A Super Administrator must manage groups used to assign an administrator role.
Custom administrator roles cannot manage groups bound to administrator role assignments. A Super Administrator must perform the operation directly, or a Super Administrator must remove the group from the administrator role assignment before the custom administrator can manage it.
NOTE: If it is unclear whether a group falls into one of the above categories, a Super Administrator can check by navigating to the group in the Admin Console and reviewing the Applications tab and Administrators tab.
