Remove user from a group

Last update:
Aug 21, 2026
Scenario
An administrator needs to remove a registered user from an application group in AIC to revoke group-scoped access or correct an incorrect membership. This is commonly required during role/team changes, offboarding, or remediation after an access review. For Policy-on applications, removing the user from the group is the required way to revoke inherited roles that cannot be revoked individually.
Prerequisites
  • Administrator has access to Users to locate the user and review current group memberships.
  • Administrator has access to Applications → Access tile to manage group membership (remove users).
  • The user is registered and searchable in AIC, and the target Group name and Application ID are identified.
  • The user’s UUID is available (used to locate the user inside the group’s Users list in the application context).
  • Administrator has confirmed there is an approved request / justification for access removal (if required by policy).
Steps
  • Identify the correct group and application (Users view - user-centric)
    1. Sign in to Aikyam Identity Console.
    2. Navigate to Users from the left navigation pane.
    3. Search for the user and open the user profile.
    4. Open the Groups tab and locate the group you need to remove.
    5. Note the Group name and the associated Application ID (you will use these in the Applications view).
    6. Copy/confirm the user’s UUID from the user profile (needed to find the user in the group Users list).
  • Remove the user from the group (Applications view - application-centric)
    1. Navigate to Applications from the left navigation pane and select the relevant application (using the noted Application ID).
    2. Open the Access tile.
    3. Click View & Update.
    4. Go to Groups, select the target group name, then open the Users section.
    5. Search for the user using the UUID and locate the correct record in the Users list.
    6. In the Action column, click Remove for the user, then confirm the removal if prompted.
    7. Verify the user no longer appears in the group Users list.
  • Validate effective access after removal (Validation- users view)
    1. Return to the user profile in Users and open the Roles tab.
    2. Select the relevant application from the Application dropdown.
    3. Confirm roles previously inherited via that group are no longer effective.
    4. (Optional) Open the Groups tab and confirm the removed group no longer appears for the user.
Note:
  • For Policy-on applications, users inherit roles through group membership; removing the user from the group revokes inherited access automatically.
  • For legacy / Policy-off applications, group membership may not grant/revoke roles automatically; revoke roles separately if required.
  • Use Activities tab to trace access changes for compliance, audits, and investigations.

On this page

Powered by Aikyam @2025 All rights reserved