An admin may want to replicate the membership of an imported Active Directory group to an Okta-sourced group, possibly as a step in removing the AD instance from which the group is sourced.
- Active Directory (AD)
- Create an Okta group that will mirror the membership of the group already imported from Active Directory. The name of the Okta group does not need to match the AD group.
- Go to Directory > Groups and click Add group.
- Enter a group name and, optionally, a description.
- Both groups will now appear in Directory > Groups. NOTE: The Okta-sourced group will display an Okta icon and the description entered during creation, while the AD-sourced group will display a Windows icon and the description of the original AD group.
- Create an Okta Group Rule to copy the group membership.
- Go to Directory > Groups and click the Rules tab.
- Click Add Rule.
- Enter a name for the rule.
- Ensure that the Use basic condition is highlighted and select Group membership in the IF field.
- Begin typing the name of the AD group in the box and select the AD group when it appears.
- In the THEN Assign to section, begin typing the name of the Okta group and select it when it appears.
- Click Save.
- Activate the newly created Okta Group Rule.
- Go to Directory > Groups and click the Rules tab.
- Find the rule that was just created and click Actions > Activate.
- In Directory > Groups, the membership of both groups should match. Open each group to confirm.
- Deactivate the Okta Group Rule. NOTE: It is critical that this rule is deactivated prior to the AD group being removed; otherwise, the rule will remove the members from the Okta-sourced group at that time.
- Go to Directory > Groups and click the Rules tab.
- Find the rule previously created and click Actions > Deactivate. Optionally, delete the rule.
NOTE: If the AD-sourced group has any application assignments that should be transferred to the Okta-sourced group, configure those application assignments on the Okta-sourced group prior to removal of the AD group to ensure there are no unwanted application unassignments.
When the AD group is removed, the membership of the Okta-sourced group will remain intact.
