Okta Users Not Deactivated by Active Directory When Assigned to Provisioning Groups
Last Updated:
Overview
Okta does not deactivate a user when the user has an individual assignment to Active Directory (AD) and membership in an AD provisioning group. This occurs because the pending group assignment prevents deactivation after Okta removes the individual assignment. To resolve this, administrators must remove the user from the Okta-AD provisioning group before deactivating the user in AD, or manually deactivate the user in Okta if the AD deactivation already occurred. The issue persists even when the Profile and Lifecycle settings dictate that Okta deactivates users when deactivated in the application.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Provisioning
- Lifecycle Management
Cause
When an Import or Just-In-Time (JIT) provisioning event detects a deactivated user in AD, Okta removes the AD individual assignment. However, if the user also belongs to an AD provisioning group, the pending group assignment activates and prevents Okta from deactivating the user.
Solution
How are users deactivated when assigned to Active Directory provisioning groups?
Administrators must remove the user from the Okta-AD provisioning group before deactivating the user in AD. If the user has already experienced deactivation in AD, manually deactivate the Okta user from the Admin Console by locating the affected user in the Directory and selecting the deactivate option.
- Navigate to the Okta Admin Console.
- Go to Directory and select People.
- Search for and select the affected user.
- Choose Deactivate.
