# Uma-policy - negative logic does not work?

**URL:** <https://forum.keycloak.org/t/uma-policy-negative-logic-does-not-work/8897>\
**Category:** Getting advice\
**Created:** [May 4, 2021, 9:37pm UTC](https://forum.keycloak.org/t/uma-policy-negative-logic-does-not-work/8897 "2021-05-04T21:37:36Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![butch.achievers](https://avatars.discourse-cdn.com/v4/letter/b/7993a0/32.png) [@butch.achievers](https://forum.keycloak.org/u/butch.achievers)\
**Post date:** [May 4, 2021, 9:37pm UTC](https://forum.keycloak.org/t/uma-policy-negative-logic-does-not-work/8897/1 "2021-05-04T21:37:36Z")

</div>

I’m looking for advice on what I’m doing wrong regarding the usage of uma-policies.

I’ve set up a very simple policy on my resource that I would expect to evaluate to “deny to users in these groups”:

[  
{  
“id”:“8a828ce7-b095-4f47-8aca-82e63e407e6a”,  
“name”:“pk\_1\_ash\_test\_1\_not\_groups”,  
“description”:“users not in these groups”,  
“type”:“uma”,  
“scopes”:[“view”],  
“logic”:“NEGATIVE”,  
“decisionStrategy”:“AFFIRMATIVE”,  
“owner”:“7eb2166b-37f8-493e-9e46-deb52bc85307”,  
“groups”:[“/pk\_1\_1”]  
}  
]

Evaluation of this policy gives the opposite of what i’d expect.

I attempted to upload a second screenshot of the groups the user is a member of (/pk\_1\_1), but because i’m a new member it won’t let me.

If the user was in “pk\_1\_1” group, would this policy not DENY for the user?

 ![Screen Shot 2021-05-04 at 5.34.57 PM](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/6/6114dc564bf6c2a16911b45b8e75a961e3ef4fd2.png)
