user is not assigned to this application" Okta app error
Fixes Okta app errors where the user is not assigned to the application by adding the assignment directly or through a group. Use when login succeeds at the IdP but the app refuses with a not-assigned error. Not for SSO failures where authentication itself fails.
TL;DR
The user authenticated fine but has no assignment to the app. Okta separates authentication (who you are) from app assignment (what you may open). Assign the user in the app's Assignments tab and have them retry.
"user is not assigned to this application" Okta app errorUse this when
- The user passes Okta login but the app shows a not-assigned error.
- The failure is per-user while others can open the app.
- The user was recently created or moved teams.
Not for this skill when
- Okta login itself fails. That is an authentication problem.
- The app loads but shows its own permission error. That is in-app authorization.
- Every user fails. That is an app config problem, not assignment.
Steps
- In Okta Admin, open the app and then its Assignments tab. Verify: you can see who is currently assigned.
- Confirm the user, or a group containing the user, is missing from the list. Verify: the gap is real, not a display lag.
- Assign the user directly, or add them to an assigned group. Verify: the assignment appears.
- Have the user retry opening the app, clearing the app session if needed. Verify: the app opens.
- If groups drive assignment, confirm the group rule actually includes the user. Verify: rule evaluation shows them as a member.
Variant phrasings
Okta app access denied
The generic phrasing.
"not assigned" error
The short message search.
Okta 403 app
The status-first phrasing.
Compatibility: Okta app assignments, Classic and Okta Identity Engine. Applies to SAML, OIDC, and SWA apps.
Why it happens
Assignment is the authorization gate for Okta apps. New hires, team movers, and users added to the wrong group authenticate successfully and then hit the wall at the app because nobody granted them the assignment.
Edge cases / pitfalls
- Group rules with exclusions can silently skip the user; read the rule, do not assume membership.
- App-level sign-on policies can deny even assigned users; check the app's own policy.
- The user may be in the group but group push is not the same as assignment; both may be needed.
- Just-in-time provisioning can create the app account without an Okta assignment when the flows are misaligned.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_AXZAgCLHl6CVn68hCX9BGQ