<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
AD-Sourced User Accounts Show a Deactivated Status in Okta
Okta Classic Engine
Directories
Overview

Active Directory (AD) sourced user accounts show a deactivated status in Okta when the account is deactivated in AD or moved to an Organizational Unit (OU) that is not synced with Okta. Resolve this issue by reactivating the account in AD, restoring it to a synced OU, or adding the correct OU to the directory configuration in Okta.

Applies To
  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • Organizational Unit (OU)
Cause

Okta deactivates AD-sourced accounts under the following scenarios:

  • The account is deactivated in AD.
  • The account is moved to an OU in AD that is not synced with Okta.
Solution

What steps resolve the deactivated status for Active Directory sourced accounts?

 

To resolve an issue where an account is deactivated in AD, reactivate the account in the directory, verify the lifecycle sourcing settings in Okta, and run an import.

  1. Reactivate the account in AD.
  2. Verify that user reactivation from AD is enabled in Okta under Profile & Lifecycle Sourcing.

Profile & Lifecycle Sourcing

 

  1. Run an import from AD to Okta.

 

To resolve an issue where the account has been moved to an OU that is not synced with Okta, either update the directory configuration in the Okta Admin Console to add the user's new OU to Okta scope or restore the account to a synced OU in Active Directory, and run an import from AD to update the Okta user status.

 

  1. In the Okta Admin Console, navigate to Directory > Directory Integrations > [AD] > Provisioning > Integration.
  2. Under User OUs connected to Okta, select the new OU in which the user's AD account is now located to add the location to Okta import scope.

Image - Okta AD integration - user OU selection

 

  1. Alternatively, move the user's AD account to one of the OUs already selected.
  2. Perform an import from AD to update the Okta user status.
Loading
AD-Sourced User Accounts Show a Deactivated Status in Okta