
j8ot6 (j8ot6) asked a question.
On application assignment, if deleting an individual user, while included in group assignment, the user will not be able to login anymore, unless re-added to the group. This is very confusing to many users who will be working with Check Point integration and we wanted to know if there's any plan to change this behavior

Hi @j8ot6 (j8ot6) , Thank you for reaching out to the Okta Community!
If I understood the use case correctly, you handle the application assignment via Group but for whatever reason needed to remove an individual.
To re-add the user and having them be "in-line" with the rest, you can simply re-assign the user to the app individually then use the "Convert Assignment" feature to have to inherit the Group assignment as the rest of them.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope it helps!
Thank you @Mihai Negoita - Okta (Okta, Inc.) for responding.
The problem occurs when we had a user assigned to the application as part of a group and also as an individual. when removed the individual, although we expected the user to have access because of being included in the group, it didn't work that way until re-added to the group.
We have concerns that many Check Point customers who will use this integration will encounter this unexpected behavior and have trouble resolving it.
Removing the user from the assignment would not trigger a new evaluation. If the user needs to have the app but you want the assignment to be handled via Groups, then you will have to leverage the "convert assignment" feature mentioned above.
Another thing that might not come into play but just crossed my mind:
If you are by chance using Group Rules for user management, you might want to check if users have been perhaps added to the exception list.