Okta Advanced Server Access Group Push Fails With Linked Group Is Missing Error
Last Updated:
Overview
Okta generates a linked group missing error when pushing groups to Okta Advanced Server Access (ASA) due to Active Directory (AD) changes or inactive users. Resolve this issue by unlinking and repushing the group or reactivating the affected user in the ASA dashboard. When pushing groups by rule or by name to ASA, Okta displays the following error:
Linked Group is missing in Okta Advanced Server Access. Change the linked group to resume pushing group memberships
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
Cause
This error occurs due to one of the following reasons:
- Changes occur in Active Directory (AD), such as moving groups from one Organizational Unit (OU) to another.
- A user account in ASA is inactive, and that user belongs to a group assigned for pushing.
Solution
How is the group push error resolved for Active Directory changes?
Unlink the pushed group in the Okta Admin Console, delete the group in the target application, and repush the group to resolve the error caused by Active Directory (AD) changes.
- Navigate to the Okta Advanced Server Access application in the Okta Admin Console.
- Click the Push Groups tab.
- Click the Errors dropdown and select Unlink Pushed Group.
- Select Delete the Group in the Target App (Recommended).
- Click Refresh App Groups.
- Deactivate and reactivate the rule to repush the group if a rule deleted the group, or manually repush the group by name.
- Log in to the ASA dashboard and verify that the group appears.
Resolve the Group Push Error for Inactive Users in Okta Advanced Server Access
Compare the users in the failed group with the user status on the ASA dashboard, reactivate any inactive users, and retry the task in the Okta Admin Console.
- Compare users in a failed group with their status on the ASA dashboard. If multiple group pushes fail, select the group with the fewest members and compare each user in that group to their status on the ASA dashboard.
- Reactivate the user in the ASA dashboard after identifying the inactive user.
- Retry the tasks in the Okta Admin Console.
