Deactivating and deleting an Active Directory integration in Okta requires specific prerequisites, such as disabling Delegated Authentication and ensuring all connected users have Okta passwords. Deactivate the directory first before permanently deleting it from the Okta Admin Console.
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Active Directory (AD)
What are the prerequisites for deactivating an Active Directory integration in Okta?
Before deactivating an AD integration in Okta, ensure the environment meets the following conditions:
- The directory is not configured as a source for Okta users.
- Ensure that Allow Active Directory to source Okta users is cleared in the Provisioning > To Okta section of the directory integration.
- Okta is not configured to update or create users in Active Directory.
- Verify that the Update User Attributes and Deactivate Users options in the Provisioning > To App section of the integration are cleared.
- Delegated Authentication is disabled.
- Ensure that Enable delegated authentication to Active Directory is cleared in the Integration section of the directory. See How to Disable Okta Delegated Authentication for Active Directory for details.
- All connected users have Okta passwords.
- An Okta password can be set when disabling Delegated Authentication in the integration, or AD passwords can be migrated to Okta. See Password migration from AD to Okta.
NOTE: Engage consulting services through the assigned Account Executive for major infrastructure changes such as this, as Okta Support cannot assist with these actions.
How is an Active Directory integration deactivated and deleted in Okta?
Deactivate the Active Directory integration and permanently delete it from the Okta Admin Console by completing the following instructions.
- Navigate to Directory > Directory Integrations, then open the Active Directory integration to be deactivated.
- Open the dropdown menu next to Active at the top of the window and select Deactivate.
The directory appears under the Inactive tab of the Directory Integrations page.
- Select the directory in the Inactive list to proceed with deleting the directory from Okta.
- NOTE: Once deleted, a directory integration cannot be restored.
- Open the dropdown menu next to Inactive at the top of the window and select Delete.
