Okta Custom Admin Roles Require All Groups Resource to Create New Groups
Last Updated:
Overview
When configuring Okta custom admin roles, Okta requires the All Groups resource to grant administrators the ability to create new groups. Excluding a single group from the resource set automatically removes the permission to create new groups. Create a resource set containing the All Groups resource and avoid setting any exclusions to ensure administrators retain the ability to create groups.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Custom Admin Roles
- Groups
Solution
Okta requires the All Groups resource to create new groups.
To allow an administrator to create new groups using a custom admin role, the resource set must include the All Groups resource. If the resource set excludes even one group, Okta revokes the permission to create new groups. Assign the All Groups resource fully without any exclusions when configuring the custom admin role for group creation.
How do administrators configure a resource set with the All Groups resource?
Navigate to the Administrators section in the Admin Console, create a new resource set, and add the All Groups resource to grant the necessary permissions.
- In the Admin Console, navigate to Security, and then select Administrators.
- Select the Resources tab.
- Select Create new resource set.
- Enter a name and description for the resource set.
- Select Add resource.
- Choose User groups from the resource type dropdown menu.
- Select All groups.
- Select Save.
Excluding a group from the resource set revokes creation permissions.
Locate the group resource settings and observe the exclusion feature to understand how modifying it affects group creation permissions.
- Locate the User groups resource within the resource set configuration.
- Select the pencil icon next to the All groups assignment.
- In the pop-up window, observe the condition dropdown menu that allows setting the condition to Exclude.
- The Select groups dropdown menu where specific group names can be typed and selected to be excluded.
NOTE: Even if all groups are initially selected, configuring an exclusion in this pop-up immediately revokes the permission to create new groups.
