- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Active Directory (AD)
- Provisioning
How to deprovision a user from Active Directory when the user is deactivated in Okta?
Follow the video or the steps below to configure the Active Directory integration to deprovision users automatically.
- Ensure the Active Directory service account used for the Okta AD Agent has sufficient permissions to deactivate Active Directory users. See About Okta service account permissions for more information.
- Open the Directory integration in Okta.
- Select the Provisioning tab and navigate to To App.
- Select Edit at the top of the Settings section.
- Select the checkbox next to Deactivate Users and select Save.
Okta disables their Active Directory accounts when their Okta account is deactivated.
