Group Name Not Allowed Error During Group Push in Okta Advanced Server Access
Last Updated:
Overview
Okta generates a group name not allowed error during a group push in Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA) when a group uses a reserved name. Resolve this issue by assigning a non-reserved name to the affected group. When attempting to push a group with a reserved name, Okta displays the following error and image:
Unable to update Group Push mapping target App group Power Users: Error while creating user group Power Users: Bad Request. Errors reported by remote server: Group name 'Power Users' is not allowed
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Okta Privileged Access (OPA)
Cause
The error occurs because the assigned group name is included in the list of reserved group names for Okta Advanced Server Access (ASA) and Okta Privileged Access (OPA), which cannot be used for group pushes.
Solution
How is the group name not allowed error resolved?
Assign a non-reserved name to the affected group.
- Change the name of the affected group to a value that is not included in the reserved group names list.
Review the following list of case-insensitive reserved group names that cannot be used in Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA).
"sft-admin"
"root"
"sudo"
"wheel"
"account operators"
"administrators"
"backup operators"
"guests"
"power users"
"pre-windows 2000 compatible access"
"print operators"
"replicator"
"server operators"
"users"
"cert publishers"
"dhcp administrators"
"dhcp users"
"dnsadmins"
"dnsupdateproxy"
"domain admins"
"domain computers"
"domain controllers"
"domain guests"
"domain users"
"enterprise admins"
"group policy creator owners"
"ras and ias servers"
"schema admins"
"wins users"
