<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y000091IJbYSAWOkta Classic EngineAdministrationAnswered2025-03-30T09:02:20.000Z2020-07-20T12:15:29.000Z2020-07-21T14:07:29.000Z

zjicp (zjicp) asked a question.

How to create Read Only User That Can View Certain Groups

Is there a way to create a Read Only user for particular groups? For example, John Smith has read only access to Group A and Group B. Requirement is that John Smith cannot create, update or delete users in Group A and Group B. This user is only allowed to Read. I tried creating a user with Read and Group access but the user is able to create, update and delete users on the groups they have access to.


  • sandeepk.84743 (Wipro Technologies)

    Go to Security --->Administrator & click on Add administrator. select the Read Only Admin Role & Group Admin Role. Select the Groups you want the user to Administer. It should work.

     

  • zjicp (zjicp)

    Please read the last sentence in my initial post. If I add admin to Read Only and Group admin this gives the user the ability to create, update and delete users on the groups they have access to. This is not the desired result. We only want to grant read only access without the ability to create, update and delete users.

  • User15851122134349081871 (North Central-Enterprise)

    What if you just do the Read-Only Admin, then? They won't be able to create or delete users, nor change group memberships. I don't think you can restrict this to only reading certain groups, though, if that's important.

  • zjicp (zjicp)

    That would be ideal. However, when I grant Read Only admin perms to my test user, they are basically getting a view from the top of the world. Basically seeing almost everything a Super Admin can.

     

    This wouldn't be ideal as that is a little too powerful in terms of what the user can see. In addition, users in this group can even create API tokens (not sure what else a Read only can do) which doesn't sit well.

    Expand Post
  • User15851122134349081871 (North Central-Enterprise)

    Yeah, custom Admin roles is a feature that's been asked for by many Okta customers, and it is one we're working on. You can find its entry on the public roadmap page under the Planned category, and follow the specific enhancement idea.

This question is closed.
Loading
How to create Read Only User That Can View Certain Groups