Okta Best Practices for Disabling Provisioning With Group Push
Last Updated:
Overview
When administrators disable provisioning for an application, Okta Group Push may continue to function for certain System for Cross-domain Identity Management (SCIM) applications. Administrators must manually deactivate or unlink pushed groups and group push rules to prevent synchronization issues.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- System for Cross-domain Identity Management (SCIM)
- Group Push
Solution
What steps disable pushed groups and rules when turning off provisioning?
Deactivate or unlink pushed groups in the Okta Admin Console to prevent synchronization issues when disabling application provisioning.
- Navigate to Applications > Applications, select the application, and click the Push Groups tab.
- Click the Active drop-down menu for the desired group.
- Select Deactivate Group Push if provisioning will be activated in the future.
- Alternatively, select Unlink pushed group, choose either Delete the group in the target app or Leave the group in the target app, and click Unlink.
Deactivate or delete group push rules in the Okta Admin Console to stop automated group synchronization.
- Navigate to Applications > Applications, select the application, and click the Push Groups tab.
- Select the By Rule tab.
- Click the Active drop-down menu for the desired rule.
- Select Deactivate Rule if provisioning will be activated in the future, or select Delete rule to remove it permanently.
