This article explains that users are unable to remove their account from Okta Verify if their user account has been deleted from Active Directory (AD).
- Okta Verify
- Active Directory
- Android
- iOS
- macOS
- Windows
When a user is deleted from Active Directory, the link between the Okta user profile and the Active Directory (AD) user is severed. This can prevent the user from being able to remove their Okta Verify enrollment directly from their device.
To resolve this issue, the user enrollment must be deleted from the Admin Dashboard. This can be done by following these steps:
- Navigate to Directory > People in the Okta Admin Console.
- Search for and select the affected user.
- Select the More Actions button.
- Select Reset Authenticators.
- Select the specific Okta Verify enrollment to remove or choose to remove all authenticators.
- Select the Reset button to confirm.
