<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Custom Admin Roles Require All Groups Resource to Create New Groups

Okta Classic Engine
Okta Identity Engine
Administration

Overview

When configuring Okta custom admin roles, Okta requires the All Groups resource to grant administrators the ability to create new groups. Excluding a single group from the resource set automatically removes the permission to create new groups. Create a resource set containing the All Groups resource and avoid setting any exclusions to ensure administrators retain the ability to create groups.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Custom Admin Roles
  • Groups

Solution

Okta requires the All Groups resource to create new groups.

 

To allow an administrator to create new groups using a custom admin role, the resource set must include the All Groups resource. If the resource set excludes even one group, Okta revokes the permission to create new groups. Assign the All Groups resource fully without any exclusions when configuring the custom admin role for group creation.

 

How do administrators configure a resource set with the All Groups resource?

 

Navigate to the Administrators section in the Admin Console, create a new resource set, and add the All Groups resource to grant the necessary permissions.

  1. In the Admin Console, navigate to Security, and then select Administrators.
  2. Select the Resources tab.
  3. Select Create new resource set.
  4. Enter a name and description for the resource set.
  5. Select Add resource.
  6. Choose User groups from the resource type dropdown menu.
  7. Select All groups.
  8. Select Save.

 

Excluding a group from the resource set revokes creation permissions.

 

Locate the group resource settings and observe the exclusion feature to understand how modifying it affects group creation permissions.

  1. Locate the User groups resource within the resource set configuration.
  2. Select the pencil icon next to the All groups assignment.
    Resource set information  
  3. In the pop-up window, observe the condition dropdown menu that allows setting the condition to Exclude.
  4. The Select groups dropdown menu where specific group names can be typed and selected to be excluded.
    Edit groups  

 

NOTE: Even if all groups are initially selected, configuring an exclusion in this pop-up immediately revokes the permission to create new groups.

Loading
Okta Custom Admin Roles Require All Groups Resource to Create New Groups | Okta Support