<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Custom Admin Roles Require All Applications Resource to Create New Applications

Okta Classic Engine
Okta Identity Engine
Administration

Overview

When configuring Okta custom admin roles, Okta requires the All Applications resource to grant administrators the ability to create new applications. Excluding a single application from the resource set automatically removes the permission to create new applications. Create a resource set that includes the All Applications resource, and avoid setting any exclusions to ensure administrators can still create applications.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Custom Admin Roles
  • Application Resources

Solution

Okta requires the All Applications resource to create new applications.

 

To allow an administrator to create new applications using a custom admin role, the resource set must include the All Applications resource. If the resource set excludes even one application, Okta revokes the permission to create new applications. Assign the All Applications resource fully without any exclusions when configuring the custom admin role for application creation.

 

How do administrators configure a resource set with the All Applications resource?

 

Navigate to the Administrators section in the Admin Console, create a new resource set, and add the All Applications resource to grant the necessary permissions.

  1. In the Admin Console, navigate to Security, and then select Administrators.
  2. Select the Resources tab.
  3. Click Create new resource set.
  4. Enter a name and description for the resource set.
  5. Click Add resource.
  6. Choose Applications from the resource type dropdown menu.
  7. Select All Applications.
  8. Click Save.

 

Excluding an application from the resource set revokes creation permissions.

 

Locate the application resource settings and observe the exclusion feature to understand how modifying this setting impacts application creation permissions.

  1. Locate the Applications resource within the resource set configuration.
  2. Click the pencil icon next to the All applications assignment.
    Resource set information  
  3. In the pop-up window, observe the condition dropdown menu with the condition set to Exclude.
  4. The Select applications dropdown menu is where specific application names can be typed and selected to be excluded.
    Edit apps and instances  

 

NOTE: Even if all applications are initially selected, configuring an exclusion in this pop-up immediately revokes the permission to create new applications.

Loading
Okta Custom Admin Roles Require All Applications Resource to Create New Applications | Okta Support