<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Revert an Okta User to Policy

Identity Governance
Okta Classic Engine
Okta Identity Engine

Overview

Okta Identity Governance (OIG) Policies automatically assign entitlements to users. If an administrator grants a user custom entitlements via the Application Programming Interface (API) or the Okta Admin Console, future policy jobs stop running against that user. Reverting the user to Policy strips away custom entitlements and restores the automated policy engine evaluation for that user.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Identity Governance (OIG) Entitlements
  • Okta Identity Governance API
  • Okta Workflows

Solution

How is a user reverted to Policy using the Okta Admin Console?

Revert a user to Policy in the Okta Admin Console to strip away custom entitlements and restore automated policy evaluation.

  1. Log in to the Okta Admin Console as a Super Administrator.
  2. Locate the application where the user has assigned entitlements.
  3. Locate the user and select the three dots menu on the right side.
    three dots menu
  4. Select the View entitlements option. A new window opens on the right side showing any entitlements. Select the entitlement to see the source, such as Policy, Self Service Access Request, or Admin.
    entitlements
    If an administrator, API, or Access Request granted the user a custom entitlement directly, the entitlements appear as shown in the following image.
    entitlements
  5. Select the Edit button and locate the Revert to Policy button.
    Edit entittlements 
  6. Select the Revert button to complete the action.
    &quot;Revert&quot; button

The user now receives entitlements directly from any Policy rules that apply going forward.

Entitlements

 

How is a user reverted to Policy using the Okta Identity Governance API?

Execute the Grant API endpoint with the specific application and user identifiers to revert a user to Policy programmatically.

  1. Visit the Okta Identity Governance API documentation to locate the API reference for Grants.
  2. Run the Grant API using the following URL and body format. Replace <OktaDomainName>, <Application ID>, and <User ID> with the specific environment values.
    • URL: https://<OktaDomainName>/governance/api/v1/grants
    • Body:
      {
      "grantType": "POLICY",
      "target": {
      "externalId": "<Application ID>",
      "type": "APPLICATION"
      },
      "targetPrincipal": {
      "externalId": "<User ID>",
      "type": "OKTA_USER"
      }
      }
  1. Run this API call for each user to revert the user back to Policy.

 

Looking for Okta Identity Governance help? Visit the Okta Identity Governance Product Hub or schedule Office Hours with the Okta Identity Governance team.

To view feature requests and upvote product enhancement requests, please visit Okta Ideas.

 

 

Related References

Loading
Revert an Okta User to Policy | Okta Support