<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Domain Local AD Groups Do Not Show Cross Domain Membership
Directories
Overview
Domain Local Active Directory (AD) Groups imported into Okta will not show members from other domains. This article explains why.
Applies To
  • Directories

  • Active Directory

  • Domain Local Groups

Cause
Syncing membership of Domain Local AD groups from domains other than the group's own domain is not supported by Okta.
Solution

According to Microsoft Best Practices regarding when to use groups with domain local scope, domain local groups should be assigned to local resources and contain groups with a Global Scope rather than direct members from another domain.

Loading
Domain Local AD Groups Do Not Show Cross Domain Membership