<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Allow User Removal from Application Assignments Using Custom Admin Roles
Administration
Okta Classic Engine
Okta Identity Engine
Overview

This article describes how to create a custom admin role that supports removing users from application assignments.

Applies To
  • Custom Admin Roles
  • Application Assignments
Cause

Custom admin roles with only the Edit user's application assignments and Edit application's user assignments permissions can assign users to applications, but can no longer remove them.

 

When the custom admin only has these permissions, the Assignments tab of an application (in the Admin Console under Applications > Applications > Application Name) will not display any user assignment details. Since user removals are performed from this tab, the admin cannot remove users from the application. 

Assignments

Solution

To allow user removal from application assignments, add the "View application and their details" permission to the custom admin role. 

 

  1. In the Admin Console, go to Security > Administrators.
  2. Select the Roles tab from the top or Custom roles from Administrator's Overview section.

Overview

  1. Check for the custom admin role that needs to be updated, select Edit > Edit role

Attribute

  1. Ensure the following role permissions are selected:
    •  User
      • Edit the user's application assignments.
    • Application
      • View the application and its details.
      • Edit the application's user assignments.

User

Application

  1. Upon completion, select the Save role button located at the top right of the Edit role section.

Edit role

Loading
How to Allow User Removal from Application Assignments Using Custom Admin Roles