
EricK.85454 (Customer) asked a question.
403 insufficient_scope when updating user risk through Identity Threat Protection API
Hi Okta Community,
We are receiving a 403 Forbidden error when our automation attempts to update a user’s risk through the Okta Identity Threat Protection User Risk API.
The failing module is:
oktaitp.upsertUserRisk_******
The API response includes the following authentication header:
WWW-Authenticate: Bearer
authorization_uri="https://abcd-dev.okta-gov.com/oauth2/v1/authorize",
realm="https://abcd-dev.okta-gov.com",
scope="okta.userRisk.manage",
error="insufficient_scope",
error_description="The access token provided does not contain the required scopes.",
resource="/api/v1/users"
Other relevant details:
HTTP status: 403 Forbidden
Endpoint family: /api/v1/users
Error type: HTTP Request Error
Okta request ID: ********
Timestamp: Mon, 21 Sep 2026 16:45:42 GMT
We understand the request requires the okta.userRisk.manage OAuth scope. We are looking for confirmation of the complete required configuration for a service integration to perform user-risk updates:
- Must okta.userRisk.manage be granted to the OIDC/API service app and included in the token request?
- Is a particular admin role or custom role permission also required for the service app—for example, User Risk management permission or Super Admin?
- Are there any Identity Threat Protection feature, entitlement, or API-access prerequisites that must be enabled?
- After updating the app’s scopes/roles, is minting a new token sufficient, or are there additional steps needed for the integration?
We have not included tokens, client credentials, or user identifiers. Any guidance or a reference configuration for this API would be appreciated.
Thank you.

Hello @EricK.85454 (Customer) Thank you for posting on our Community page!
You are receiving a 403 Forbidden error with an insufficient_scope
error when your service integration attempts to call the Okta Identity Threat Protection User Risk API to update user risk levels, and you need confirmation of the complete OAuth scope, role, and feature configuration required for this integration to succeed.
The error indicates that your access token does not include the okta.userRisk.manage
OAuth scope. Here is the complete configuration checklist:
Solution:
Additional verification steps:
We hope this resolves the issue.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.