
zazo5 (zazo5) asked a question.
We've got some external folks that occasionally will need specific app access that we don't want provisioned into other apps. Is our best bet for this just to not use "Everyone" at all and just stick to other app assignment groups instead, or is there a way to exclude individuals or groups from being effected by "Everyone" in some way?

Hi Ryan,
As best practice, we don’t recommend using the “Everyone” group for application assignments (although I understand it’s convenience) as there is no way to remove users from it besides completely deleting the user account.
To answer your question, there is no way to exclude users from the “Everyone” group or it’s app assignments. You can however, unassign users from an application that has been assigned through the “Everyone” group by overriding the app assignment type (by choosing Assignment master>Administrator (overrides group)). However, this might not be a permanent solution as any event that might trigger the user group memberships re-evaluation, could result in the user being re-assigned to the app.
In conclusion, the best way to handle app assignments is, as you mentioned, by using dedicated groups.
Regards,
Mihai Negoita
Technical Support Engineer
Okta Global Customer Care