<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00007i84MRSAYOkta Classic EngineAdministrationAnswered2024-04-15T12:50:30.000Z2020-02-05T13:19:44.000Z2020-02-10T06:54:28.000Z
Custom Admin Role - Possible?

Is it possible to customize admin levels in order to reduce risk?

 

For example - Could an admin role be created that allows only app provisioning and token resets? Is it possible to get more granular and allow only certain apps to be provisioned by this admin account?

 

Business Case - Risk would like to reduce the number of "global admins" for lack of a better term. I want to balance the risk out and still allow IT support to fully assist end users.

 

Business Case * 2 - We have a Workday integration and there is concern that team members could change the SSO login to an incorrect team member and see their beneficiaries and other personal data. If I could remove Workday application assignment to a few admins, that would ease their concern.


  • Update - I see an application admin that can perform this role. However, when I added a user to application admin, they lost Help Desk admin. I then added both of them at the same time after removing App Admin.

     

    I think I am close. Is there a way to allow assignment to all applications except a few? For example, I could remove the assignment capability for the Workday integration. This would address the Risk department concerns.

    Expand Post
  • i9l8o (i9l8o)

    This was the response I received from Okta Support.

     

    Unfortunately, at this moment, there is no such feature, however I recommend you to create a feature request in our community forums. When you’re in Okta Admin portal > Help & Support > Go to Ideas and submit this in your own words. This is the model going forward to empower Okta admin to make requests, and to solicit input from the community who also share your desire for this enhancement, not to mention it can be tracked while going forward. I hope this information will be of help.

    Expand Post
This question is closed.
Loading
Custom Admin Role - Possible?