Okta Just-In-Time Provisioning Deactivates Users When Active Directory Acts as the Second Profile Source
Last Updated:
Overview
Okta Just-In-Time (JIT) provisioning deactivates user accounts when Active Directory (AD) acts as the second profile source, Profile and Lifecycle Sourcing settings dictate user deactivation, and AD marks the user as inactive. This is expected behavior, as the first profile source only applies to attribute updates, while any profile source updates the user status. Okta deactivates users even when AD is not the primary profile source.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Just-In-Time (JIT) Provisioning
- Real-Time Sync
- Active Directory (AD)
Cause
Okta JIT provisioning deactivates user accounts when all of the following conditions exist:
- Active Directory acts as the second profile source.
- Profile and Lifecycle Sourcing settings dictate user deactivation.
- Active Directory marks the user as inactive.
Solution
Why does Okta deactivate users when Active Directory acts as the second profile source?
This is expected behavior. The first profile source applies only when Okta updates an attribute on the user profile. Any configured profile source updates the user status.
