# OpenID Connect group can kick users out of all unsynced groups

**URL:** https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416
**Category:** Bug
**Tags:** sso, openid-connect
**Created:** [7 mei 2026 om 17:46 UTC](https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416 "2026-05-07T17:46:29Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![Steradiant](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steradiant/32/360541_2.png) [@Steradiant](https://meta.discourse.org/u/Steradiant)
#### Post date: [7 mei 2026 om 17:46 UTC](https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416/1 "2026-05-07T17:46:29Z")

</div>

Under certain conditions, the OpenID Connect group sync **kicks users out of all Discourse groups** without a synced oidc group.

The logs and overall situation indicate that this is triggered when a user looses a single (unsynced) oidc group. The system apparently intends to kick the user out of the single group (which doesn’t exist), as it uses the group name of the lost group in its change note.  
But instead, it kicks them out of all unsynced groupo.

Considering the loss of access this can trigger, I consider this a quite high-priority bug.

---

_[View the full topic](https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416)._
