<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta LDAP Organizational Units for Users Remain Unchanged After Group Changes

Okta Classic Engine
Directories
Okta Identity Engine

Overview

When an Okta-sourced user moves to a group provisioned to a Lightweight Directory Access Protocol (LDAP) directory with a different Organizational Unit (OU), the provisioned LDAP user's OU remains unchanged because Okta disables the feature to support user moves across OUs by default. Administrators must enable the Early Access feature for LDAP OU moves and configure the directory integration to update the OU upon group changes. Specifically, if an Okta-sourced user belongs to a group provisioned to an LDAP directory with one OU, and the user moves to a different group provisioned to a different OU, the provisioned user's OU in the LDAP directory fails to update.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Directories
  • Lightweight Directory Access Protocol (LDAP)

Cause

The Early Access feature that supports user moves across OUs in LDAP integrations remains disabled, or the directory integration lacks the configuration to update the OU when the provisioning group changes.

Solution

How is the LDAP Organizational Unit updated when a user changes groups?

Enable the Early Access feature for user moves across OUs in the Okta Admin Console and configure the specific directory integration to update the user attributes upon group changes.

  1. Navigate to the Okta Admin Console and select Settings, followed by Features.
  2. Scroll to the Support user moves across OUs in LDAP option and enable the toggle.

The following image shows the Early Access feature toggle enabled, which supports user moves across OUs in LDAP.

The Support user moves across OUs in LDAP toggle enabled in the Okta Admin Console

  1. Navigate to Directory, select Directory Integrations, and choose the specific LDAP integration.
  2. Select the Provisioning tab and choose To App.
  3. Scroll to Update User Attributes and enable the Update OU when the group that provisions a user to LDAP changes option.

The following image displays the enabled option to update the OU when the group that provisions a user to LDAP changes.

The Update OU when the group that provisions a user to LDAP changes option enabled in the Provisioning tab

Loading
Okta LDAP Organizational Units for Users Remain Unchanged After Group Changes | Okta Support