Reprovisioning a Deactivated Active Directory Account Skip to main content
https://support.okta.com/help/oktaarticledetailpage?childcateg=&id=ka0f0000000ay3fkag&source=documentation&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fdocumentation%2fknowledge_article%2f27916016-reprovisioning-a-deactivated-active-directory-account
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Reprovisioning a Deactivated Active Directory Account
Published: Jan 12, 2015   -   Updated: Jun 22, 2018


When you disable an Active Directory (AD) account, Okta's automated deprovisioning feature removes app assignments, deactivates the associated Okta user account, and disables any user-management-supported apps. If the deprovisioning workflow does not occur automatically, you are notified of the required steps on your Administrator Dashboard.

Okta now supports two methods of automated account reactivation (Note: both methods are Early Access features.  Contact support if you'd like to enable one or both methods):

  • JIT Reactivation will reactivate a deactivated user's account upon login into Okta if that user's account has been reactivated or re-enabled in Active Directory
  • Profile Sync Reactivation will reactivate a deactivated user's account upon an import operation from Active Directory

To manually reactivate a deactivated account that was imported from a source directory, perform the following steps:

  1. Reactivate the user's account in Active Directory
  2. In Okta Admin Console, navigate to Directory > People and find the user who needs to be reactivated
  3. Click the Activate Person button in the upper-right
  4. Run an import from AD. We recommend that you perform a full import to ensure that AD finds the user's record.
  5. Confirm and activate the user in the Import Results screen,