Okta LDAP Organizational Units for Users Remain Unchanged After Group Changes
Last Updated:
Overview
When an Okta-sourced user moves to a group provisioned to a Lightweight Directory Access Protocol (LDAP) directory with a different Organizational Unit (OU), the provisioned LDAP user's OU remains unchanged because Okta disables the feature to support user moves across OUs by default. Administrators must enable the Early Access feature for LDAP OU moves and configure the directory integration to update the OU upon group changes. Specifically, if an Okta-sourced user belongs to a group provisioned to an LDAP directory with one OU, and the user moves to a different group provisioned to a different OU, the provisioned user's OU in the LDAP directory fails to update.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Lightweight Directory Access Protocol (LDAP)
Cause
The Early Access feature that supports user moves across OUs in LDAP integrations remains disabled, or the directory integration lacks the configuration to update the OU when the provisioning group changes.
Solution
How is the LDAP Organizational Unit updated when a user changes groups?
Enable the Early Access feature for user moves across OUs in the Okta Admin Console and configure the specific directory integration to update the user attributes upon group changes.
- Navigate to the Okta Admin Console and select Settings, followed by Features.
- Scroll to the Support user moves across OUs in LDAP option and enable the toggle.
The following image shows the Early Access feature toggle enabled, which supports user moves across OUs in LDAP.
- Navigate to Directory, select Directory Integrations, and choose the specific LDAP integration.
- Select the Provisioning tab and choose To App.
- Scroll to Update User Attributes and enable the Update OU when the group that provisions a user to LDAP changes option.
The following image displays the enabled option to update the OU when the group that provisions a user to LDAP changes.
