<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00009hLuEpSAKOkta Classic EngineAdministrationAnswered2025-10-09T20:48:44.000Z2020-10-15T11:16:59.000Z2020-11-05T17:06:31.000Z

2vvfu (2vvfu) asked a question.

Administer groups and permissions without administering apps

Is it possible for an administrator to be able to administer which groups can use which apps (and which permissions a group has for each app) *without* giving that administrator permissions to "Add Apps" or edit existing app config?

 

Thanks!


  • rohern (Okta)

    Hi Harry,

    If you are asking about creating a SWA app with an additional field, search the OIN for "Template". The SWA template you are looking for, I believe, is Template Plugin App 3 fields. There are several other Templates available, but pretty sure that will get you the extra field you need.

     

    Expand Post
    • template app
  • Here are the admin roles with their specific permission https://help.okta.com/en/prod/Content/Topics/Security/administrators-admin-comparison.htm.

    For your specific request, you can assign to users specific groups and applications admin permissions. This will grant them the ability to assign specific groups to specific applications(that they administrate) and they will not be able to add any new applications. The only limitation is that when they do have admin rights over an application they will be able to modify the application configuration.

    Expand Post
  • 2vvfu (2vvfu)

    Great, thanks. So I think I cannot do my use case: allow an admin to be able to create groups, and assign applications to that group (with specific permissions), and then assign that group to users, but NOT alter how the application is configured.

     

    OK, I believe that means more up front work to define the groups and permissions, then allow admins to just use those groups. That should work. Thanks!

    Expand Post
This question is closed.
Loading
Administer groups and permissions without administering apps