AD group Skip to main content
https://support.okta.com/help/answers?id=9062a000000bmrpqay&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fanswers
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Balazs VargaBalazs Varga 

AD group

Hello All,

I have two domains in trusted relation. I created a universal group in domain A and put a user inside, then I created a domain local group on domain B and add domain A's universal group as member. I ran a manual import on okta (on both domain) and saw the group is empty. Does the okta has any restriction related to group types ? 

Another question is how can I delete a group from okta? I created then deleted a group in my domain, but I still see it in okta. 

Thanks 

Jerrell GaryJerrell Gary (Okta, Inc.)
Hello Balazs,

Here is a KB article about AD Groups:

https://support.okta.com/help/articles/Knowledge_Article/FAQ-Okta-and-AD-Groups


Here is a KB article about Managing Groups in Okta:

https://support.okta.com/help/articles/Knowledge_Article/92113353-Importing-and-Using-Groups-in-Okta

If you want to remove an AD Group from Okta you must make sure the group you want to remove is outside the of Okta's AD import sync. For example, if you initially imported an AD group into Okta from an OU that was scanned by Okta, you have two options for removing the AD group:

1) Moving the group to another OU which Okta does not scan. Then running a Full import into Okta.

2) Unchecking the OU within Okta so Okta will not scan where the group resides and then running a Full Import into Okta.

 
Balazs VargaBalazs Varga

Thanks for the response. My problem is the domains are not under the same forest.

So I have 2 different domains run on 2 different servers and I set a trusted relationship between them. As I know I cannot use universal group on Domain A if I  want to add user from domain B to That SG in domain A.

I would like to manage users in one group in Domain A. Is it possible ?

Thanks