<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000AE6HR5CQNOkta Identity EngineIdentity GovernanceAnswered2024-08-20T15:57:38.000Z2024-08-19T07:00:22.000Z2024-08-20T15:46:34.000Z
Access Certifications not revoke user after reviewer select revoke

Hi Okta team,

 

 

Can you help me why Access Certifications was not revoke when reviewer selected revoke ?

the issue was found when we review resouce by group but individual not found

/help/servlet/rtaImage?refid=0EM4z000008eMzv

This result test revoke but in group still not revome

/help/servlet/rtaImage?refid=0EM4z000008eN00

 

this campiagn setting

/help/servlet/rtaImage?refid=0EM4z000008eN05

 


  • @PhitchayaphatmethinT.49052 (Customer)​ There's typically a couple reasons why this would happen. First, if the user is assigned to a group via group rules. Secondly, if the group being reviewed is assigned to multiple applications. Either scenario we can't or won't remove (because of potential impacts to other apps) the user from the group. In the group rule scenario, the admin can add them as an exception or the you can decide on if this group should be sourced via a group rule going forward or not. Typically a group rule is used because users should get access from a birth right perspective. Another way to address this IMO is to use the group rule to pre-populate the list of users. Then disable group rule and select the option to retain the users in that group. Now, setup an Access Request using Resource Centric Access Requests (RCAR) to manage who is in the group. Now, if a campaign is run and user is revoked, they will be removed from the group.

     

    Hope this helps and happy governing!

    Christian

    Expand Post
    Selected as Best
  • @PhitchayaphatmethinT.49052 (Customer)​ There's typically a couple reasons why this would happen. First, if the user is assigned to a group via group rules. Secondly, if the group being reviewed is assigned to multiple applications. Either scenario we can't or won't remove (because of potential impacts to other apps) the user from the group. In the group rule scenario, the admin can add them as an exception or the you can decide on if this group should be sourced via a group rule going forward or not. Typically a group rule is used because users should get access from a birth right perspective. Another way to address this IMO is to use the group rule to pre-populate the list of users. Then disable group rule and select the option to retain the users in that group. Now, setup an Access Request using Resource Centric Access Requests (RCAR) to manage who is in the group. Now, if a campaign is run and user is revoked, they will be removed from the group.

     

    Hope this helps and happy governing!

    Christian

    Expand Post
    Selected as Best
  • Normally you get "Manual Remediation" for Group rules. So it leads me to think its because the group rule is the issue. Please let me know if this helps.

This question is closed.
Loading
Access Certifications not revoke user after reviewer select revoke