Skip to content
Last updated on

Permissions

Permissions allow the principal to perform tasks and access resources in Okta. When you create a custom role, you can define a specific set of permissions to access specific resources. Principals assigned to the custom role are limited to the specific permissions and resources defined.

See the permissions catalog for a complete set of Okta permissions. Each permission entry describes the permission with references to applicable resources, included permissions, and related permissions:

  • Applicable resources: Resources that apply to the granted permission. For example, the okta.users.read permission grants you access to read Okta user resources.

  • Included permissions: Permissions that are implicitly granted through the main permission. For example, the okta.agents.manage permission also includes the okta.agents.read permission. Therefore, if you grant the okta.agents.manage permission to a user, the user is also granted the okta.agents.read permission.

  • Related permissions: Okta recommends that you grant any related permission along with the main permission for the typical use case requiring the main permission. The principal may experience unintended behaviors if you don't also grant the related permission.

Some Okta API resource operations indicate the permissions required to access the operation for common use cases. See IAM access to API resources.

Notes:

Permissions conditions

You can also add conditions to certain permissions. These conditions modify which attributes an admin with a custom role can create, see, or edit in a user profile. See Permission conditions.

You can add conditions if the custom admin role has one of the following permissions:

Permissions catalog

The following permissions are supported in Okta.

okta.agents.manage

DescriptionAllows the admin to manage agent communication and agent updates
Applicable resourcesAll agents
Included permissionsokta.agents.read

okta.agents.read

DescriptionAllows the admin to download agents and view agent statuses
Applicable resourcesAll agents

okta.agents.register

DescriptionAllows the admin to register agents and domains
Applicable resourcesAll agents
Related permissionsokta.agents.manage

okta.apps.assignment.manage

DescriptionAllows the admin to manage assignment operations of an app in your Okta org and view the following provisioning errors: app assignment, group push mapping, and Error Profile push updates.
Applicable resourcesAll apps, all apps of a specific type, a specific app

okta.apps.clientCredentials.read

DescriptionAllows the admin to view information about client credentials for the app
Applicable resourcesAll apps, all apps of a specific type, a specific app

okta.apps.manage

DescriptionAllows the admin to fully manage apps and their members in your Okta org
Applicable resourcesAll apps, all apps of a specific type, a specific app
Included permissionsokta.apps.read, okta.apps.assignment.manage, okta.apps.clientCredentials.read

okta.apps.manageFirstPartyApps

DescriptionAllows the admin to manage first-party apps
Applicable resourcesAll access requests
Related permissionsokta.apps.read

okta.apps.read

DescriptionAllows the admin to only read information about apps and their members in your Okta org
Applicable resourcesAll apps, all apps of a specific type, a specific app

okta.apps.universalLogout.manage

DescriptionAllows the admin to manage universal logout settings for apps
Applicable resourcesAll apps, all apps of a specific type, a specific app
Included permissionsokta.apps.universalLogout.read
Release Version2025.11.0

okta.apps.universalLogout.read

DescriptionAllows the admin to view universal logout settings for apps
Applicable resourcesAll apps, all apps of a specific type, a specific app
Release Version2025.11.0

okta.authzServers.manage

DescriptionAllows the admin to manage authorization servers
Applicable resourcesAll authorization servers, a specific authorization server

okta.authzServers.read

DescriptionAllows the admin to read authorization servers
Applicable resourcesAll authorization servers, a specific authorization server

okta.customizations.manage

DescriptionAllows the admin to manage customizations
Applicable resourcesAll customizations
Included permissionsokta.customizations.read

okta.customizations.read

DescriptionAllows the admin to read customizations
Applicable resourcesAll customizations

okta.devices.lifecycle.activate

DescriptionAllows the admin to activate devices
Applicable resourcesAll devices

okta.devices.lifecycle.deactivate

DescriptionAllows the admin to deactivate devices. When you deactivate a device, it loses all device user links.
Applicable resourcesAll devices

okta.devices.lifecycle.delete

DescriptionAllows the admin to permanently delete devices
Applicable resourcesAll devices

okta.devices.lifecycle.manage

DescriptionAllows the admin to perform any device lifecycle operations
Applicable resourcesAll devices
Included permissionsokta.devices.lifecycle.activate, okta.devices.lifecycle.deactivate, okta.devices.lifecycle.suspend, okta.devices.lifecycle.unsuspend, okta.devices.lifecycle.delete

okta.devices.lifecycle.suspend

DescriptionAllows the admin to suspend device access to Okta
Applicable resourcesAll devices

okta.devices.lifecycle.unsuspend

DescriptionAllows the admin to unsuspend and restore device access to Okta
Applicable resourcesAll devices

okta.devices.manage

DescriptionAllows the admin to manage devices and perform all device lifecycle operations
Applicable resourcesAll devices
Included permissionsokta.devices.read, okta.devices.lifecycle.manage

okta.devices.read

DescriptionAllows the admin to read device details
Applicable resourcesAll devices

okta.directories.manage

DescriptionAllows the admin to manage all directory integration settings of an app instance
Applicable resourcesAll directory integrations, a specific type of directory integration, a specific directory integration
Included permissionsokta.directories.read

okta.directories.read

DescriptionAllows the admin to view the directory integration settings of an app instance
Applicable resourcesAll directory integrations, a specific type of directory integration, a specific directory integration

okta.eventhooks.manage

DescriptionAllows the admin to manage event hooks in your Okta org
Applicable resourcesAll event hooks
Included permissionsokta.eventhooks.read
Release Version2025.12.0

okta.eventhooks.read

DescriptionAllows the admin to view event hooks in your Okta org
Applicable resourcesAll event hooks
Release Version2025.12.0

okta.governance.accessCertifications.manage

DescriptionAllows the admin to view and manage access certification campaigns
Applicable resourcesAll access certifications

okta.governance.accessRequests.manage

DescriptionAllows the admin to view and manage access requests
Applicable resourcesAll access requests

okta.governance.labels.manage

DescriptionAllows the admin to create, update, delete and assign labels in your org
Applicable resourcesAll apps, all groups, all governance collections, all entitlement bundles, all entitlement values
Included permissionsokta.governance.labels.read
Release Version2025.12.0

okta.governance.labels.read

DescriptionAllows the admin to view labeled resources in your org.
Applicable resourcesAll apps, all groups, all governance collections, all entitlement bundles, all entitlement values
Release Version2025.12.0

okta.groups.appAssignment.manage

DescriptionAllows the admin to manage a group's app assignment (also need okta.apps.assignment.manage to assign to a specific app)
Applicable resourcesAll groups, a specific group

okta.groups.create

DescriptionAllows the admin to create groups
Applicable resourcesAll groups

okta.groups.manage

DescriptionAllows the admin to fully manage groups in your Okta org
Applicable resourcesAll groups, a specific group
Included permissionsokta.groups.create, okta.groups.read, okta.groups.members.manage, okta.groups.appAssignment.manage

okta.groups.members.manage

DescriptionAllows the admin to only manage member operations in a group in your Okta org
Applicable resourcesAll groups, a specific group
Related permissionsokta.users.groupMembership.manage

okta.groups.read

DescriptionAllows the admin to only read information about groups and their members in your Okta org
Applicable resourcesAll groups, a specific group

okta.iam.read

DescriptionAllows the admin to view roles, resources, and admin assignments
Applicable resourcesAll Identity and Access Management resources

okta.identityProviders.manage

DescriptionAllows the admin to manage Identity Providers
Applicable resourcesAll Identity Providers
Included permissionsokta.identityProviders.read

okta.identityProviders.read

DescriptionAllows the admin to read Identity Providers
Applicable resourcesAll Identity Providers

okta.inlinehooks.manage

DescriptionAllows the admin to manage inline hooks in your Okta org
Applicable resourcesAll inline hooks
Included permissionsokta.inlinehooks.read
Release Version2025.12.0

okta.inlinehooks.read

DescriptionAllows the admin to view inline hooks in your Okta org
Applicable resourcesAll inline hooks
Release Version2025.12.0

okta.policies.manage

DescriptionAllows the admin to manage policies
Applicable resourcesAll policies
Included permissionsokta.policies.read
Release Version2025.05.0

okta.policies.read

DescriptionAllows the admin to view any policy
Applicable resourcesAll policies
Release Version2025.05.0

okta.profilesources.import.run

DescriptionAllows the admin to run imports for apps with a profile source, such as HRaaS and AD/LDAP apps. Admins with this permission can create users through the import.
Applicable resourcesAll apps, all apps of a specific type, a specific app

okta.realms.manage

DescriptionAllows the admin to view, create, and manage realms
Applicable resourcesAll realm resources
Included permissionsokta.realms.read

okta.realms.read

DescriptionAllows the admin to view realms
Applicable resourcesAll realm resources

okta.ssf.securityEventsProviders.manage

DescriptionAllows the admin to manage shared signals framework receivers
Applicable resourcesAll shared signals framework receivers
Included permissionsokta.ssf.securityEventsProviders.read
Release Version2025.05.0

okta.ssf.securityEventsProviders.read

DescriptionAllows the admin to view shared signals framework receivers
Applicable resourcesAll shared signals framework receivers
Release Version2025.05.0

okta.support.cases.manage

DescriptionAllows the admin to view, create, and manage Okta Support cases
Applicable resourcesAll Okta Support cases opened by the admin

okta.users.apitokens.clear

DescriptionAllows the admin to clear user API tokens
Applicable resourcesAll users, all users within a specific group
Release Version2025.05.0

okta.users.apitokens.manage

DescriptionAllows the admin to manage API tokens
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.apitokens.read, okta.users.apitokens.clear

okta.users.apitokens.read

DescriptionAllows the admin to view API tokens
Applicable resourcesAll users, all users within a specific group

okta.users.appAssignment.manage

DescriptionAllows the admin to manage a user's app assignment (also need okta.apps.assignment.manage to assign to a specific app)
Applicable resourcesAll users, all users within a specific group

okta.users.create

DescriptionAllows the admin to create users. If the admin is also scoped to manage a group, that admin can add the user to the group on creation and then manage.
Applicable resourcesAll groups, a specific group

okta.users.credentials.expirePassword

DescriptionAllows the admin to expire a user's password and set a new temporary password
Applicable resourcesAll users, all users within a specific group

okta.users.credentials.manage

DescriptionAllows the admin to manage only credential lifecycle operations for a user
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.credentials.resetFactors, okta.users.credentials.resetPassword, okta.users.credentials.expirePassword

okta.users.credentials.manageTemporaryAccessCode

DescriptionAllows admin to view, create and delete a user's temporary access code
Applicable resourcesAll users, all users within a specific group
Release Version2025.07.2

okta.users.credentials.resetFactors

DescriptionAllows the admin to reset MFA authenticators for users
Applicable resourcesAll users, all users within a specific group

okta.users.credentials.resetPassword

DescriptionAllows the admin to reset passwords for users
Applicable resourcesAll users, all users within a specific group

okta.users.groupMembership.manage

DescriptionAllows the admin to manage a user's group membership (also need okta.groups.members.manage to assign to a specific group)
Applicable resourcesAll users, all users within a specific group
Related permissionsokta.groups.members.manage

okta.users.lifecycle.activate

DescriptionAllows the admin to activate user accounts
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.clearSessions

DescriptionAllows the admin to clear all active Okta sessions and OAuth 2.0 tokens for a user
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.deactivate

DescriptionAllows the admin to deactivate user accounts
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.delete

DescriptionAllows the admin to permanently delete user accounts
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.manage

DescriptionAllows the admin to perform any user lifecycle operations
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.lifecycle.activate, okta.users.lifecycle.deactivate, okta.users.lifecycle.suspend, okta.users.lifecycle.unsuspend, okta.users.lifecycle.delete, okta.users.lifecycle.unlock, okta.users.lifecycle.clearSessions

okta.users.lifecycle.suspend

DescriptionAllows the admin to suspend user access to Okta. When a user is suspended, their user sessions are also cleared.
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.unlock

DescriptionAllows the admin to unlock users who have been locked out of Okta
Applicable resourcesAll users, all users within a specific group

okta.users.lifecycle.unsuspend

DescriptionAllows the admin to restore user access to Okta
Applicable resourcesAll users, all users within a specific group

okta.users.manage

DescriptionAllows the admin to create and manage users and read all profile and credential information for users. Delegated admins with this permission can only manage user credential fields and not the credential values themselves.
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.create, okta.users.read

okta.users.read

DescriptionAllows the admin to read any user's profile and credential information. Delegated admins with this permission can only manage user credential fields and not the credential values themselves.
Applicable resourcesAll users, all users within a specific group

okta.users.risk.manage

DescriptionAllows the admin to provide user risk feedback and elevate user risk
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.risk.read
Release Version2025.05.0

okta.users.risk.read

DescriptionAllows the admin to view user risk
Applicable resourcesAll users, all users within a specific group
Release Version2025.05.0

okta.users.userprofile.manage

DescriptionAllows the admin to only perform operations on the user object, including hidden and sensitive attributes
Applicable resourcesAll users, all users within a specific group
Included permissionsokta.users.userprofile.read

okta.users.userprofile.read

DescriptionAllows the admin to view profile of a user
Applicable resourcesAll users, all users within a specific group
Release Version2025.08.0

okta.workflows.invoke

DescriptionAllows the admin to view and run delegated flows
Applicable resourcesAll delegated flows, a specific delegated flow

okta.workflows.read

DescriptionAllows the admin to view delegated flows
Applicable resourcesAll delegated flows, a specific delegated flow