Skip to main content
Version: 1.28 (Current)

Revoke User Role

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, User management

Removes one or more security roles from users. The roles are removed from the current user and from every user in the context's list of users.

In a form, the current user is usually the logged-in user. Use Load User or Load Users from SQL to pick other users. Users who don't have the role are skipped without an error.

For how roles are used in Plant an App, see Roles.

Typical Use Cases​

  • Remove a trial or subscription role when a user cancels
  • Take away access from a group of users loaded with Load Users from SQL
  • Move a user from one role to another, together with Grant User Role

Don't use it to​

Action NameDescription
Grant User RoleGrants roles to the current user and to every user in the list, or to one user.
Load UserLoads users into the list and makes the last one the current user.
Load Users from SQLAdds the users returned by a SQL query to the list.
Change UserChanges the current user without adding it to the list.
Unauthorize UserStops users from logging in.
Delete RoleDeletes a role.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
RoleThe role to remove, picked from the portal's roles. In expression mode, enter role IDs or role names, separated by commas, for example [RoleId].YesemptyNo
Other Role NamesMore roles to remove, as role names or role IDs, separated by commas, semicolons or new lines, for example Trial, Newsletter. They're removed together with Role.Yesempty stringNo

You need at least one role in Role or Other Role Names. If none of them match a role, the action does nothing.

Output Parameters Reference​

This action has no output parameters.

Considerations​

  • There's no permission check in the action. Anyone who can run it can remove any role from the users in context. Only put it where you control who runs it.
  • Don't build roles from values the user sends. If Role or Other Role Names use tokens from form fields, the query string or an API request, a user can change them and remove other roles.
  • The current user loses the role too. In a form, that's usually the person who clicked. If you only load other users, the logged-in user still loses the role. To avoid that, change the current user first with Load User.
  • Check who's in the list. Every loaded user loses the role. Users loaded earlier in the same run are still in the list. See Load User.
  • Some roles can't be removed. DNN doesn't remove anyone from Registered Users, and doesn't remove the portal's main administrator from Administrators. These are skipped without an error.
  • Numbers are always role IDs. In Other Role Names, a value like 2024 is looked up as a role ID, not a role name. Role names that don't exist are skipped without an error.
  • No email is sent. The user isn't notified.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Remove the Trial role from the current user​

This action removes the Trial role from the current user.

{
"Title": "Revoke User Role",
"ActionType": "RevokeUserRole",
"Description": "Remove the Trial role",
"Parameters": {
"RoleId": {
"Expression": "",
"Value": "",
"IsExpression": false,
"Parameters": {}
},
"RoleNames": "Trial"
}
}

2. Remove a role from a selected user​

These actions load the user whose ID is in the UserId token, then remove the role with ID 8 from that user. Because Load User makes that user the current user, the logged-in user keeps the role. The condition makes sure the user was found. Otherwise, the logged-in user would still be the current user and would lose the role.

{
"Title": "Load User",
"ActionType": "LoadUser",
"Description": "Load the selected user",
"Parameters": {
"Id": "[UserId]",
"Portal": ""
}
}
{
"Title": "Revoke User Role",
"ActionType": "RevokeUserRole",
"Description": "Remove the role from the selected user",
"Condition": "\"[User:UserID]\" == \"[UserId]\"",
"Parameters": {
"RoleId": {
"Expression": "",
"Value": "8",
"IsExpression": false,
"Parameters": {}
},
"RoleNames": ""
}
}

Revised 09/28/2026