This article provides steps for administrators to switch user profile sourcing and provisioning from an existing Okta Integration Network (OIN) application, such as Workplace by Meta, to Active Directory (AD).
- Active Directory (AD)
- Okta Integration Network (OIN)
- Profile Sourcing
- Provisioning
Please read through the Best Practices when Switching from One Profile Source to Another Okta Doc beforehand.
To switch profile sourcing to Active Directory (AD), perform the following steps:
- Stop provisioning from the current source application:
- In the Okta Admin Console, navigate to the provisioning-enabled Okta Integration Network (OIN) application (for example, Workplace by Meta).
- Select the Provisioning tab.
- Disable any active provisioning features (for example, Create Users, Update User Attributes, or Deactivate Users).
- Set AD as the new profile source:
- Ensure all relevant user accounts in Okta are linked to their corresponding AD accounts.
- In the Admin Console, go to Directory > Profile Sources.
- Set AD as the highest-priority profile source by placing it at the top of the list.
- Review and compare attribute mappings between the OIN app and AD to prevent unwanted updates, as AD will now overwrite conflicting attributes in Okta.
- Remove the Workplace App:
- After confirming that AD is the active profile source and all users are properly linked, safely remove the OIN application from Okta.
- Removing the app will not affect users as long as their profiles are sourced from AD.
NOTE:
- Before making these changes, review group memberships and any dependencies on attributes from the original application.
- Test thoroughly in a lower environment before doing it in production.
- Test the process with a small group of users, if possible, to ensure a smooth transition.
