Allowing User Removal From Application Assignments by Using Custom Admin Roles in Okta
Last Updated:
Overview
Custom administrator roles with only the Edit user's application assignments and Edit application's user assignments permissions can assign users to applications, but cannot remove them. When the custom administrator only has these permissions, the Assignments tab of an application does not display any user assignment details. Adding the View application and their details permission to the custom administrator role resolves the issue and allows user removal.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Custom Admin Roles
- Application Assignments
Cause
Custom administrator roles with only the Edit user's application assignments and Edit application's user assignments permissions can assign users to applications but cannot remove them. Since user removals are performed from the Assignments tab, the administrator cannot remove users from the application without the ability to view the details.
Solution
How can an Okta Administrator create a custom admin role to allow user removal from application assignments?
To allow user removal from application assignments, add the View application and their details permission to the custom administrator role.
- In the Admin Console, go to Security > Administrators.
- Select the Roles tab, or select Custom roles from the Administrator's Overview section.
- Find the custom admin role that requires the update, then select Edit > Edit role.
- Ensure these role permissions are selected:
- User
- Edit the user's application assignments
- Application
- View the application and its details
- Edit the application's user assignments
- User
- Select Save role at the top right of the Edit role section.
