<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How Okta Manages AD Groups After OU Changes
Directories
Okta Identity Engine
Overview

This article provides information on how Okta handles changes for Active Directory Group when moved across Organizational Units (OUs) for the existing groups that were assigned to applications for assignments and/or push groups, which are sourced by Active Directory and synced as imported groups to Okta.

Applies To
  • Active Directory (AD)
  • Lifecycle Management
  • Okta Integration Network (OIN)
  • Active Directory Imported Groups
  • Push Groups
  • Okta Identity Engine (OIE)
Solution

Imported Active Directory groups that are moved across Organizational Units (OUs) and used for application(s) assignments and push group configurations will not cause users to lose access/be deprovisioned to apps or affect the Okta environment. A full import before moving Groups in AD to a different Organizational Units (OUs) is recommended to ensure all new data is reflected in Okta from Active Directory.

Loading
How Okta Manages AD Groups After OU Changes