Manage user entitlements

You may need to review or edit an individual user's entitlements. This could occur if the user's project assignment changes, they need access to entitlements for a short interval, or they no longer need access to certain entitlements.

Before you begin

  • Sign in as a super admin, an app admin, or an admin with the following permissions:

    • Manage applications
    • Edit application's user assignments
    • Edit groups' application assignments or Edit users' application assignments
  • Enable Entitlement management for the app and create entitlements, if you haven't already done so.
  • Ensure that the app is assigned to the user.
  • Optional. Enable the Access requests conditions and Resource catalog feature to view or change user's access expiration for the entitlements and apps.

Procedure

  1. In the Admin Console, go to Applications and Resources > Applications.

  2. Select an app.

  3. Go to the Assignments tab.

  4. Open the options menu associated with the user.

  5. Click View access details.

  6. On the Entitlements panel, click Edit or Manage access.

  7. Optional. Remove entitlement bundles that Access Requests assigned to the user.

  8. Optional. You can remove an individual entitlement by clicking the X beside the entitlement. Click Revoke entitlement on the dialog that appears. Repeat this step to remove more individual entitlements.
  9. Optional. Click Assign entitlements to individually assign more entitlements to the user.
    1. Choose from the available entitlement values to assign entitlements to the user.
    2. Click Add entitlement to add another entitlement.
    3. Click Assign. Entitlements added this way are labeled Admin assigned on the Manage access page.
  10. Optional. Click Convert to policy to have the user receive entitlements based on policy.
    1. Select Merge to have the user receive entitlements based on the policy and keep any bundles and additional entitlements from custom grants, or choose Policy Only (revoke existing grants) to have the user receive entitlements through the policy and have all other bundles and entitlements be revoked. In the latter case, policy rules are then used to govern the user's entitlements. If the user's profile attributes meet the conditions of policy rules, entitlements are assigned to the user.
    2. Click Apply selection.
  11. Optional. Click Edit expiration associated with an entitlement to update the duration of user's access to the entitlement. Follow the prompts in the UI to set the access duration and click Save. It may take a few minutes after the expiration for Okta to revoke the user's access.

  12. Optional. Click Edit expiration beside App access at the top of the Manage access page to update the duration of the user's access to the app. Follow the prompts in the UI to set the access duration and click Save. It may take a few minutes after the expiration for Okta to revoke the user's access.

    The app access expiration that you set must not be less than the access expiration of any entitlement bundles assigned to the user.