Okta Org2Org Incremental Import Fails to Remove Deactivated Users
Last Updated:
Overview
Org2Org incremental imports look for changes rather than syncing the entire user detail, which may cause Okta to omit updates when an administrator moves a user entirely outside the scope of the API integration.
Resolve this issue by running full imports or deactivating the user in the source before descoping them. For example, if an administrator suspends and descopes (removes from applications) an Okta user in a source org, Okta does not pass the changes to the target org using incremental imports.
Applies To
- Okta Identity Engine (OIE)
- Provisioning
- Org2Org
- Incremental imports
Cause
Org2Org incremental imports look for changes rather than syncing the entire set of user details. When an administrator moves users entirely outside the scope of the Org2Org API integration, the incremental import does not detect the change, regardless of whether the user status is active, deactivated, or suspended.
Solution
How does Okta remove deactivated users during an Org2Org incremental import?
When Okta deactivates a user via incremental imports (with Profile & Lifecycle Sourcing set to Deactivate when a user is deactivated in the app), the user remains within scope. However, when an administrator moves users entirely outside the scope of the API integration, incremental imports do not detect the change.
Ensure Okta removes deactivated users by running full imports or deactivating the user before descoping them using one of the following methods.
- Run occasional full imports. The Early Access (EA) Cron-based User Import scheduling feature assists with this process.
- Deactivate the user in the source before decoping them.
