<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Troubleshooting Admin Role Campaigns

Identity Governance
Okta Classic Engine
Okta Identity Engine

Overview

Admin role-centric access certification campaigns enable organizations to align access privileges with the principle of least privilege, granting users only the necessary access required to fulfill their responsibilities. This approach minimizes the risk of unauthorized access, insider threats, and data breaches, as access permissions are tailored to each individual's role and responsibilities.  

To deliver the most impactful access certification reviews for the organization’s most sensitive resources, having the ability to review at the user level is a security must. Due to the sensitivity of Administrative roles, certain campaigns with reviewers are not supported. This article will highlight what is supported and which combinations are not.

Applies To

  • Access Certifications of Admin Roles

Solution

Assumptions

  • Self-review is not supported for Admin Roles.
  • Manager and Group reviews always use Fallback Reviewer.
  • Group Owner reviewer is not supported.

 

Scenarios 

Scenario 1 = User added to campaign is also selected as Reviewer
 
Scenario 2 = User added to campaign is identified as their own Manager, Manager selected as reviewer
 
Scenario 3 = User added to campaign is also added to the Group selected as reviewer
 
Scenario 4 = Group owner not supported
 
Scenario 5 = User added to campaign and Custom reviewer via expression option is selected.
 

 

Scenario 1

If the user is targeted as the resource of a campaign and is added as the Reviewer.  The subsequent campaign will fail with the following error:



<user> cannot be assigned their own review item because self-review is disabled for this campaign.

Result: denied 

Scenario 2A

If the user is targeted as the resource of a campaign and is also mapped in the profile as their own manager for review.  Another user is assigned as the Fallback reviewer.   Because the fallback reviewer is not the target of the review, they will be automatically selected as the reviewer.

Result: approved 

Scenario 2B

If the user is targeted as the resource of a campaign and is also mapped in the profile as their own manager for review. The same user is also assigned as the Fallback reviewer.   Because the fallback reviewer is the same as the manager and is the target of the review, this campaign will fail with the following error:
 
<user> cannot be assigned their own review item because self-review is disabled for this campaign.
 

Result: denied

Scenario 2C

If the user is targeted as the resource of a campaign and is not mapped in the profile as their own manager for review. The same user is selected as the Fallback Reviewer. Because the user's manager is not defined as themself, this review will succeed, as the fallback reviewer is not needed.
 

Result: approved

Scenario 2D

If the user is targeted as the resource of a campaign and is not mapped in the profile as their own manager for review, but the user who is mapped is not active within Okta. The Fallback Reviewer is set to the user being reviewed. This campaign will fail because the Fallback reviewer will be the same as the reviewer.  This campaign will fail with the following error:
<user> cannot be assigned their own review item because self-review is disabled for this campaign.

Result: denied

Scenario 3A

If the user is targeted as the resource of a campaign and is the only member of a group assigned as the Group Reviewer. This means the User is self-reviewing.  This campaign will fail with the following error:


<user> cannot be assigned their own review item because self-review is disabled for this campaign.

Result: denied

Scenario 3B

If the user is targeted as the resource of a campaign, and the user is not the only member of a group that is assigned as the Group Reviewer.  This means the User is self-reviewing, except that there are other users in the group. The campaign will succeed, but the user will not be included as a reviewer in the campaign.

Result: approved

Scenario 4

If a user is targeted as the resource of a campaign, Group Owner is not supported. Therefore, this type of campaign cannot be created. 

Result: denied

Scenario 5A

If the user is targeted as the resource of a campaign, and the custom option is selected as the reviewer.  If the custom expression does not resolve the user being reviewed, this campaign succeeds. 

Result: approved

Scenario 5B

If the user is targeted as the resource of a campaign, and the custom option is selected as the reviewer.  If the custom expression resolves the user being reviewed, but the Fallback Reviewer is not the same user, then this campaign succeeds using the user resolved in the expression.  Fallback Reviewer is not used.

Result: approved

Scenario 5C

If the user is targeted as the resource of a campaign, and the custom option is selected as the reviewer.  If the custom expression does not resolve the user being reviewed, but the Fallback Reviewer is the same user, then this campaign succeeds because the Fallback Reviewer is used. 

Result: approved

Scenario 5D

If the user is targeted as the resource of a campaign, and the custom option is selected as the reviewer.  If the custom expression resolves the user being reviewed, and the Fallback Reviewer is the same user, then this campaign fails because the resolved reviewer and Fallback Reviewer are the same as the user being reviewed.  This campaign will fail with the following error: 


<user> cannot be assigned their own review item because self-review is disabled for this campaign.

Result: denied

 

Related References

 

Loading
Okta Support - Troubleshooting Admin Role Campaigns