Renamed Active Directory Organizational Units Do Not Sync Okta
Last Updated:
Overview
Active Directory (AD) Organizational Units (OUs) stop syncing with Okta when the OU name changes in AD. Refreshing the application data and reselecting the renamed OU in the directory integration settings resolves this issue. When this synchronization failure occurs, Okta clears the OU selection under the AD settings and deactivates users in the renamed OUs after an AD import.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Active Directory (AD) Import
Cause
The name of the Organizational Unit (OU) changes in Active Directory (AD).
Solution
How is the Active Directory Organizational Unit synchronization restored?
Refresh the application data in the Okta Admin Console, reselect the renamed Organizational Unit (OU) in the Active Directory (AD) integration settings, and run an import to restore deactivated users.
- In the Okta Admin Console, go to Applications, and then select Applications.
- Select More, and then choose Refresh Application Data.
- Go to Directory, and then select Directory Integrations.
- Select the AD integration.
- Select the Provisioning tab, and then choose Integration.
- Select the newly renamed OU.
- Run an import to restore any users deactivated by the name change.
