Revoke User Role
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens,User management
Removes one or more security roles from users. The roles are removed from the current user and from every user in the context's list of users.
In a form, the current user is usually the logged-in user. Use Load User or Load Users from SQL to pick other users. Users who don't have the role are skipped without an error.
For how roles are used in Plant an App, see Roles.
Typical Use Cases
- Remove a trial or subscription role when a user cancels
- Take away access from a group of users loaded with Load Users from SQL
- Move a user from one role to another, together with Grant User Role
Don't use it to
- Stop a user from logging in. Use Unauthorize User or Delete User instead.
- Remove a role from everyone and delete it. Use Delete Role instead.
- Let users pick which role to remove in a public form. See Considerations.
Related Actions
| Action Name | Description |
|---|---|
| Grant User Role | Grants roles to the current user and to every user in the list, or to one user. |
| Load User | Loads users into the list and makes the last one the current user. |
| Load Users from SQL | Adds the users returned by a SQL query to the list. |
| Change User | Changes the current user without adding it to the list. |
| Unauthorize User | Stops users from logging in. |
| Delete Role | Deletes a role. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Role | The role to remove, picked from the portal's roles. In expression mode, enter role IDs or role names, separated by commas, for example [RoleId]. | Yes | empty | No |
| Other Role Names | More roles to remove, as role names or role IDs, separated by commas, semicolons or new lines, for example Trial, Newsletter. They're removed together with Role. | Yes | empty string | No |
You need at least one role in Role or Other Role Names. If none of them match a role, the action does nothing.
Output Parameters Reference
This action has no output parameters.
Considerations
- There's no permission check in the action. Anyone who can run it can remove any role from the users in context. Only put it where you control who runs it.
- Don't build roles from values the user sends. If Role or Other Role Names use tokens from form fields, the query string or an API request, a user can change them and remove other roles.
- The current user loses the role too. In a form, that's usually the person who clicked. If you only load other users, the logged-in user still loses the role. To avoid that, change the current user first with Load User.
- Check who's in the list. Every loaded user loses the role. Users loaded earlier in the same run are still in the list. See Load User.
- Some roles can't be removed. DNN doesn't remove anyone from
Registered Users, and doesn't remove the portal's main administrator fromAdministrators. These are skipped without an error. - Numbers are always role IDs. In Other Role Names, a value like
2024is looked up as a role ID, not a role name. Role names that don't exist are skipped without an error. - No email is sent. The user isn't notified.
Examples
To understand how to use the below examples, please see Running Examples.
1. Remove the Trial role from the current user
This action removes the Trial role from the current user.
{
"Title": "Revoke User Role",
"ActionType": "RevokeUserRole",
"Description": "Remove the Trial role",
"Parameters": {
"RoleId": {
"Expression": "",
"Value": "",
"IsExpression": false,
"Parameters": {}
},
"RoleNames": "Trial"
}
}
2. Remove a role from a selected user
These actions load the user whose ID is in the UserId token, then remove the role with ID 8 from that user. Because Load User makes that user the current user, the logged-in user keeps the role. The condition makes sure the user was found. Otherwise, the logged-in user would still be the current user and would lose the role.
{
"Title": "Load User",
"ActionType": "LoadUser",
"Description": "Load the selected user",
"Parameters": {
"Id": "[UserId]",
"Portal": ""
}
}
{
"Title": "Revoke User Role",
"ActionType": "RevokeUserRole",
"Description": "Remove the role from the selected user",
"Condition": "\"[User:UserID]\" == \"[UserId]\"",
"Parameters": {
"RoleId": {
"Expression": "",
"Value": "8",
"IsExpression": false,
"Parameters": {}
},
"RoleNames": ""
}
}
Revised 09/28/2026