Select Root and Child OUs When Pushing Groups via the Okta AD Agent
Last Updated:
Overview
When pushing groups using the Okta Active Directory (AD) Agent, the configuration prompts for a target Organizational Unit (OU). The OU picker uses a radio button and a folder icon, each serving a different purpose. Select the radio button to designate a root OU as the push target, and select the folder icon to view and select nested child OUs.
Applies To
- Okta Identity Engine (OIE)
- Okta Active Directory (AD) Agent
- Active Directory Group Push
Solution
How are root and child OUs selected during a group push?
Use the radio button to select a root OU and the folder icon to expand and view child OUs in the group push configuration.
- To select a root (parent) OU, select the radio button next to the OU entry. This action designates that OU as the push target. Selecting the radio button alone does not expand or reveal any child OUs beneath it.
- To view child OUs nested under a parent, select the folder icon next to the OU entry. Child OUs appear only after selecting the folder icon.
- To identify whether a child OU exists under a given entry, check the folder icon appearance. A bold or dark-colored folder icon indicates that the OU has one or more child OUs. Select the folder icon to expand and view them. A plain or unhighlighted folder icon indicates a leaf OU with no further nesting.
NOTE: If an administrator selects a root OU using the radio button without first expanding the folder icon, Okta targets only the parent OU. To push a group to a child OU, expand the child OU using the folder icon next to the radio button.
