
PhitchayaphatmethinT.49052 (Customer) asked a question.
Hi Okta team,
Can you help me why Access Certifications was not revoke when reviewer selected revoke ?
the issue was found when we review resouce by group but individual not found
This result test revoke but in group still not revome
this campiagn setting

@PhitchayaphatmethinT.49052 (Customer) There's typically a couple reasons why this would happen. First, if the user is assigned to a group via group rules. Secondly, if the group being reviewed is assigned to multiple applications. Either scenario we can't or won't remove (because of potential impacts to other apps) the user from the group. In the group rule scenario, the admin can add them as an exception or the you can decide on if this group should be sourced via a group rule going forward or not. Typically a group rule is used because users should get access from a birth right perspective. Another way to address this IMO is to use the group rule to pre-populate the list of users. Then disable group rule and select the option to retain the users in that group. Now, setup an Access Request using Resource Centric Access Requests (RCAR) to manage who is in the group. Now, if a campaign is run and user is revoked, they will be removed from the group.
Hope this helps and happy governing!
Christian