<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008C3jT4SAJOkta Classic EngineAdministrationAnswered2024-04-30T09:18:25.000Z2016-04-01T21:45:01.000Z2017-07-19T18:34:32.000Z

j5v7c (j5v7c) asked a question.

Only trigger group rules for active user
Is there a way to configure a group rule so it only fires for active Okta users? Currently, if I disable a user's Okta access, the group rules still fire for the user and they maintain their group memberships. This means I need to manually remove them from the groups, which creates exceptions in the group rules and is not very clean. Suggestions?

SreckoA.34303 likes this.
  • Hi Tiffany,

     

    What types of group rules is this affecting? There is currently no way to automatically remove deactivated users from the groups they were a member of. I would be interesting in hearing about some use cases where this would be beneficial.

     

    Of course you are welcome to submit this to us as a feature request using the ‘Post Idea’ button in the link below if you haven't done so already.

     

    https://support.okta.com/help/ideas/ideaList.apexp

     

    Thank you,

    Nick

    Okta Support
    Expand Post
  • j5v7c (j5v7c)

    Hi Nick,

     

    As an example, we have an API call configured that pulls all group membership to a particular Okta group to determine who needs access on a separate on-prem system. We recently encountered an issue in which an employee was terminated, but they were still members of the okta group, which meant their access to the on-prem system remained. We got lucky in that case because our operations team ran a user audit soon after and I was able to manually remove, but it could have been a very severe security issue. I have already created an idea for this issue (https://support.okta.com/help/ideas/viewIdea.apexp?id=087F0000000BF7C)
    Expand Post
This question is closed.
Loading
Only trigger group rules for active user