Remove Application-Imported Groups From Okta
Last Updated:
Overview
Administrators must remove application-imported groups from Okta when they are no longer required. Disabling the group import feature in the application provisioning settings removes all groups provisioned from the application to Okta. To remove a single group, use the Okta API.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Groups
- Provisioning
Solution
Review the Prerequisites Before Removing Imported Groups
Review the following requirements and limitations before attempting to remove imported groups from Okta.
- Remove all groups imported from an application when they are no longer required.
- Okta prevents disabling group imports when group policy rules or mappings exist, or when a group selected for deletion is assigned to an application.
- This process applies to all integrations that support the Import Groups feature.
- To remove a specific application group from Okta without removing all groups, delete the group via the Okta API.
How are all imported groups removed from an application?
Disable the group import feature in the Okta Admin Console to remove all groups provisioned from the application to Okta, as detailed in either the video demonstration or the written instructions.
- In the Okta Admin Console, navigate to Applications > Applications.
- Select the application.
- Select the Provisioning tab.
- Select Integration under Settings.
- Clear the Import Groups checkbox.
- Okta displays a notification indicating that this action deletes all groups provisioned from the application to Okta.
- Select Save.
- Okta automatically starts an import in the background to pull the new provisioning information for groups.
NOTE: If Okta does not automatically start an import, perform a manual full import or wait for the next scheduled import to delete the groups.
