<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Unable to Import the BuiltIn Container from Active Directory into Okta

Okta Classic Engine
Directories
Okta Identity Engine

Overview

Okta excludes the default BuiltIn container during Active Directory (AD) imports because AD assigns a TRUE value to the isCriticalSystemObject attribute. Okta blocks the import of any object whose value for this attribute is TRUE. Furthermore, if a group nests inside a BuiltIn group, Okta imports the child group but excludes the BuiltIn parent group, meaning Okta cannot read or display the membership of the BuiltIn group.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • Import
  • AD Schema

Cause

Okta excludes the default BuiltIn container during AD imports because the container possesses a TRUE value for the isCriticalSystemObject attribute. Okta prevents the import of any object that has a TRUE value for the isCriticalSystemObject attribute.

Solution

Why does Okta exclude the BuiltIn container during imports?

Okta excludes the default BuiltIn container, and any object that has a TRUE value for the isCriticalSystemObject attribute, during imports. Because Okta excludes this container, it does not appear as an available Organizational Unit (OU) for selection in the AD integration settings.

 

Additionally, if a group nests inside a BuiltIn group, Okta imports the child group but does not import the BuiltIn parent group. For example, if the "Organizational Administrators" group nests inside the BuiltIn "Administrators" group, Okta imports "Organizational Administrators" successfully. However, because Okta excludes the "Administrators" group, Okta cannot read or display the membership of the "Administrators" group.

Loading
Okta Support - Unable to Import the BuiltIn Container from Active Directory into Okta