Okta Group Push Common Configuration And Synchronization Issues
Last Updated:
Overview
Okta Group Push configuration and synchronization issues occur due to assignment group reuse, inactive user statuses, or deleted downstream target groups. Resolve these issues by using separate groups for assignment and push, reactivating users, and refreshing application groups. Administrators encounter various configuration and synchronization errors when managing pushed groups, preventing group membership updates in the downstream application.
Review the Group Push functionality in the Okta Admin Console.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Group Push
- Provisioning
Cause
Group Push issues occur when an assignment group is reused for Group Push, causing membership synchronization conflicts. Additionally, an inactive user status in Okta excludes users from provisioning calls, and downstream target group deletion breaks the mapped Push Group ID.
Solution
What are the common configuration issues with Okta Group Push?
Review the common configuration and synchronization issues encountered with Okta Group Push and their respective resolutions.
- Using the same Okta group for assignments and group push is not supported and may result in issues with no obvious error message. To maintain consistent group membership between Okta and the downstream app, a separate group must be created and configured to push groups to the target app.
- A pushed user must be active in Okta, assigned to the application, part of the Okta pushed group, and provisioned and active on the application side.
- Manage pushed groups only in Okta. Changing the group in the target application causes synchronization issues with Okta.
- Okta does not include deactivated users in Group Push updates, preventing group membership updates in the downstream application. Reactivate the user in Okta and run Group Push again for each group the user belongs to.
- This process is always Okta sourced. Therefore, a group name that already exists within the target app cannot be pushed unless the app supports Group Linking.
- Pushing groups to Active Directory requires the permissions to create groups in Active Directory.
- Okta does not send a call to convert a group to an application group when the group unlinks but remains undeleted.
- If the downstream application deletes the target group, remove the Push Group from the application in Okta and add it back as a Push Group.
- If Okta does not find the desired target group as a match when attempting to link to an existing group in the application, select Refresh App Groups from the Push Groups tab of the application settings.
