Enable the "Disconnect User from Active Directory" Okta Admin Permission
Last Updated:
Overview
Administrators require specific custom role permissions to view the Disconnect from Active Directory option in the More Actions dropdown menu on a user record. Assign the necessary user and application permissions to a custom administrator role and configure the corresponding resource set to enable this feature.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Custom Administrator Role
- Custom Resource
Solution
How are the custom administrator role permissions configured to enable the Disconnect from Active Directory option?
Assign the required user and application permissions to a custom administrator role and configure the corresponding resource set to enable the disconnect option.
- Assign the following permissions to the custom administrator role:
- Edit the user's lifecycle states.
- View users and their details.
- Edit user's application assignments.
- Edit application's user assignments.
Verify the custom administrator role permissions match the configurations displayed in the following images:
- Assign the following parameters to the resource set:
- Applications: All Active Directory applications.
- Users: All users.
Verify the resource set matches the configuration displayed in the following image:
