Unable to Import the BuiltIn Container from Active Directory into Okta
Last Updated:
Overview
Okta excludes the default BuiltIn container during Active Directory (AD) imports because AD assigns a TRUE value to the isCriticalSystemObject attribute. Okta blocks the import of any object whose value for this attribute is TRUE. Furthermore, if a group nests inside a BuiltIn group, Okta imports the child group but excludes the BuiltIn parent group, meaning Okta cannot read or display the membership of the BuiltIn group.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Import
- AD Schema
Cause
Okta excludes the default BuiltIn container during AD imports because the container possesses a TRUE value for the isCriticalSystemObject attribute. Okta prevents the import of any object that has a TRUE value for the isCriticalSystemObject attribute.
Solution
Why does Okta exclude the BuiltIn container during imports?
Okta excludes the default BuiltIn container, and any object that has a TRUE value for the isCriticalSystemObject attribute, during imports. Because Okta excludes this container, it does not appear as an available Organizational Unit (OU) for selection in the AD integration settings.
Additionally, if a group nests inside a BuiltIn group, Okta imports the child group but does not import the BuiltIn parent group. For example, if the "Organizational Administrators" group nests inside the BuiltIn "Administrators" group, Okta imports "Organizational Administrators" successfully. However, because Okta excludes the "Administrators" group, Okta cannot read or display the membership of the "Administrators" group.
