Okta Group Push Rules Skipped Due to Improper User Permissions
Last Updated:
Overview
A group push rule configured with a provisioning application fails to pick up newly created groups when a constrained administrator account creates them. To resolve this, assign the appropriate administrator role permissions for creating groups and managing applications, then recreate the affected groups. When a constrained Okta administrator account creates a new group, Okta generates the following error in the System Log:
Due to improper permissions from User <USER_ID> in creating GroupPushMapping(s) for UserGroup <USER_GROUP>, these GroupPushRule(s) have been skipped [grouppushruleid]
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Integration Network (OIN)
- Push Group by Rule
- Administrator Roles and Permissions
Cause
The administrator account possesses permission to create a new group but lacks the appropriate permissions to manage an application assignment as a consequence of the matching rule.
Solution
How are group push rule permission errors resolved?
Assign the appropriate administrator role permissions for creating groups and managing applications, verify dependencies, and recreate the affected groups by following these steps.
- Add the appropriate administrator role permissions for both Create groups and Manage applications. This includes the standard roles Organization Administrator and Application Administrator, or a custom role and resource set.
Review the following image for an example of the Manage Applications permissions configuration. - Check for other dependencies to ensure their removal does not cause an issue.
- Delete the recently created groups. NOTE: Contact Okta Support before deleting these recently created groups.
- Recreate the groups using an administrator account with the appropriate permissions level.
