When trying to apply a target to a task or policy, the target icons are displayed with a lock although the security role the user browsing the console is a member of is assigned to the target's scope. The lock icon implies that the user does not have rights to that Target.
Some companies have Targets created by one group and used by another group. Those companies will have to change the scope of each Target created so that they can be used by another group.
8.x
The behavior is by design.
To workaround: