okta "you are not assigned to this application" after sso login
Resolves Okta rejecting SSO with you are not assigned to this application: fixing app assignments and group rules. Use when authentication succeeds but the app denies access for assignment. Not for login failures or license problems.
TL;DR
The user authenticated fine but is not assigned to the application. Assign the user directly or through a group, check group rules that should have assigned them, and have them retry.
The query
okta "you are not assigned to this application" after sso loginUse this when
- Okta shows not assigned to this application after login
- new hires hit this on day one
- some team members access the app but others cannot
Not for
- password or MFA failures in Okta
- application-side permission errors after SSO
- deprovisioned users
Steps
- In the Okta admin console, open the application and check its Assignments tab for the user. Expected output: the user is confirmed missing from assignments.
- Check whether a group assignment or group rule should cover the user, and whether the rule actually matched them. Expected output: the intended assignment path is identified.
- Assign the user directly or fix the group rule so it matches them. Expected output: the user appears in the assignment list.
- Confirm the user has a license or seat if the app requires one. Expected output: licensing is not the blocker.
- Have the user retry the app from the Okta dashboard. Expected output: SSO completes and the app opens.
Applies to
Okta app assignments, group rules, current Okta admin console.
Variant phrasings
Assigned but still denied
Group rule timing: rules evaluate on a schedule; force a rule evaluation or wait for the next run.
Works for the user in one app but not another
Per-app assignments differ; assignment to one app never implies another.
Why it happens
Okta separates authentication from authorization per app. Passing login only proves identity; the app tile stays locked until an assignment grants access.
Edge cases
- Group rules with complex expressions silently fail to match; test the rule against the user.
- Deprovisioned-then-rehired users lose assignments; re-add them explicitly.
- Bookmarked app URLs bypass the dashboard but not the assignment check.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_zBIyEThlYRmzAly1R1BoCQ