<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Disconnecting Users from Active Directory
Okta Classic Engine
Directories
Overview
This article explains how to disconnect a user from Active Directory using the Okta Admin Console and the implications of the password reset options.
Applies To
  • User Management
  • Active Directory
  • Okta Classic Engine
Solution

To disconnect a user from Active Directory, follow the video or the steps below.



 Users can be disconnected from Active Directory individually or in bulk. To disconnect a single user:

  1. From the Okta Admin Console, navigate to Directory People and find the user that needs to be disconnected from AD.

  2. Click More Actions > Disconnect from AD.

Disconnect from AD

  1. At the confirmation screen, select a password option:
    1. Select Reset password now to have a password reset email sent to the user. By default, the link in this email will expire after one hour.
    2. Select Don't reset password if the password will be reset later or if the user will be reconnected to another source for Delegated Authentication. The user will be unable to log in until the password is set.

Disconnect User Profile from AD

To disconnect users from Active Directory in bulk:

  1. From the Okta Admin Console, navigate to Directory People.
  2. Click More Actions Disconnect from AD.

Disconnect from AD

  1. Select the users that need to be disconnected and then click the Disconnect Selected button.

Disconnect from AD

  1. At the confirmation screen, select a password option:
    1. Select Reset password now to have a password reset email sent to the user. By default, the link in this email will expire after one hour.
    2. Select Don't reset password if the password will be reset later or if the user will be reconnected to another source for Delegated Authentication. The user will be unable to log in until the password is set.

To switch users back to being AD-sourced, re-import them to link their Okta accounts to their AD accounts.

Loading
Disconnecting Users from Active Directory