
q5nrb (q5nrb) asked a question.
Hi,
Anyone able to tell if Okta is planning to add scope limitation for the Group Membership Admin role? Right now, anyone granted this role can read all the users in the directory. We sorely miss a way to limit the scope down to selective groups from where the users can be viewed/selected.
Or, if there is another way to acheive this, do share!
Thanks
Mads

Hi Mads, I'm not sure on the roadmap for Group Membership Admin role, but we do have a custom admin role coming to beta later this year. It's going to allow customers to create their own permission sets for admin roles. You might want to reach out to your CSM or Account Exec to see if they can confirm if it will provide granularity to restrict Read permissions to specific groups of users.
Thanks Rus. Yeah, there is always a new feature on the horizon ;) It just frustrates me, as scope limitation is present so many other places within Okta, I believe it to be low effort to add that to the Group Membership Admin role.