<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Users Not Deactivated by Active Directory When Assigned to Provisioning Groups

Okta Classic Engine
Okta Identity Engine
Directories

Overview

Okta does not deactivate a user when the user has an individual assignment to Active Directory (AD) and membership in an AD provisioning group. This occurs because the pending group assignment prevents deactivation after Okta removes the individual assignment. To resolve this, administrators must remove the user from the Okta-AD provisioning group before deactivating the user in AD, or manually deactivate the user in Okta if the AD deactivation already occurred. The issue persists even when the Profile and Lifecycle settings dictate that Okta deactivates users when deactivated in the application.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • Provisioning
  • Lifecycle Management

Cause

When an Import or Just-In-Time (JIT) provisioning event detects a deactivated user in AD, Okta removes the AD individual assignment. However, if the user also belongs to an AD provisioning group, the pending group assignment activates and prevents Okta from deactivating the user.

Solution

How are users deactivated when assigned to Active Directory provisioning groups?

Administrators must remove the user from the Okta-AD provisioning group before deactivating the user in AD. If the user has already experienced deactivation in AD, manually deactivate the Okta user from the Admin Console by locating the affected user in the Directory and selecting the deactivate option.

  1. Navigate to the Okta Admin Console.
  2. Go to Directory and select People.
  3. Search for and select the affected user.
  4. Choose Deactivate.
Loading
Okta Users Not Deactivated by Active Directory When Assigned to Provisioning Groups | Okta Support