<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Best Practices for Disabling Provisioning With Group Push

Lifecycle Management
Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

When administrators disable provisioning for an application, Okta Group Push may continue to function for certain System for Cross-domain Identity Management (SCIM) applications. Administrators must manually deactivate or unlink pushed groups and group push rules to prevent synchronization issues.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • System for Cross-domain Identity Management (SCIM)
  • Group Push

Solution

What steps disable pushed groups and rules when turning off provisioning?

Deactivate or unlink pushed groups in the Okta Admin Console to prevent synchronization issues when disabling application provisioning.

  1. Navigate to Applications > Applications, select the application, and click the Push Groups tab.
  2. Click the Active drop-down menu for the desired group.
  3. Select Deactivate Group Push if provisioning will be activated in the future.
    Deactivate Group Push option
  4. Alternatively, select Unlink pushed group, choose either Delete the group in the target app or Leave the group in the target app, and click Unlink.
    Unlink pushed group

 

Deactivate or delete group push rules in the Okta Admin Console to stop automated group synchronization.

  1. Navigate to Applications > Applications, select the application, and click the Push Groups tab.
  2. Select the By Rule tab.
  3. Click the Active drop-down menu for the desired rule.
    Deactivate Rule
  4. Select Deactivate Rule if provisioning will be activated in the future, or select Delete rule to remove it permanently.

 

Related References

Loading
Okta Best Practices for Disabling Provisioning With Group Push | Okta Support