<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Cannot Use AD Group Push to Manage Groups in the AWS Delegated Groups OU

Okta Classic Engine
Okta Identity Engine
Lifecycle Management
Okta Integration Network

Overview

When attempting to configure AD Group Push to manage groups within the AWS Delegated Groups OU on an AD server in AWS, the following error appears:

Unable to update Group Push mapping target App group 
{Group Name Here}: Error updating AD groups: Access is Denied.  Verify your configuration settings and if necessary delete this push group and reconfigure

 

Applies To

  • AWS Managed AD
  • Push Groups

Solution

Due to restrictive permissions on the AWS Delegated Groups Organizational Unit (OU) in Amazon's AWS Managed AD and extraneous operations performed by Okta's AD agent, Admins cannot use Okta's Push Groups feature to control membership of groups that reside in the AWS Delegated Groups OU. If Admins attempt to configure the Push Groups feature on a group that resides in the AWS Delegated Groups OU, it will fail with the following message:

Unable to update Group Push mapping target App group <group name>: Error updating AD Group: Access is denied.

Recommended content

Support Videos
Okta Support
Documentation
Group Push
Documentation
Group Push
Loading
Okta Support - Cannot Use AD Group Push to Manage Groups in the AWS Delegated Groups OU