Okta Group Push Common Issues
Last Updated:
Overview
The Group Push functionality pushes existing Okta groups and memberships to provisioning-enabled, third-party applications. Administrators encounter various configuration and synchronization issues when managing pushed groups. Review the common Group Push issues and their corresponding resolutions to ensure consistent group membership between Okta and downstream applications.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Group Push
- Provisioning
Cause
Some cause examples for this issues could be:
- Reusing an assignment group for Group Push causes membership sync conflicts.
- Inactive status in Okta excludes users from provisioning calls.
- Downstream target group deletion breaks the mapped Push Group ID.
Solution
What are the common configuration issues with Okta Group Push?
Review the common configuration and synchronization issues encountered with Okta Group Push and their respective resolutions.
- Using the same Okta group for assignments and group push is not supported and may result in issues with no obvious error message. To maintain consistent group membership between Okta and the downstream app, a separate group must be created and configured to push groups to the target app.
- A pushed user must be active in Okta, assigned to the application, part of the Okta pushed group, and provisioned and active on the application side.
- Manage pushed groups only in Okta. Changing the group in the target application causes synchronization issues with Okta.
- Okta does not include deactivated users in Group Push updates, preventing group membership updates in the downstream application. Reactivate the user in Okta and run Group Push again for each group the user belongs to.
- This process is always Okta sourced. Therefore, a group name that already exists within the target app cannot be pushed unless the app supports Group Linking.
- Pushing groups to Active Directory requires the permissions to create groups in Active Directory.
- Okta does not send a call to convert a group to an application group when the group unlinks but remains undeleted.
- If the downstream application deletes the target group, remove the Push Group from the application in Okta and add it back as a Push Group.
- If Okta does not find the desired target group as a match when attempting to link to an existing group in the application, select Refresh App Groups from the Push Groups tab of the application settings.
