Impact of Deactivating and Deleting Okta Group Rules
Last Updated:
Overview
Deactivating an Okta group rule leaves existing users in the group while preventing new assignments, whereas deleting a group rule prompts the administrator to either keep or remove the existing users.
NOTE: Deleting a group rule and removing user memberships assigned by the rule are permanent actions that administrators cannot recover or undo.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Group Rules
- Universal Directory (UD)
- Okta Expression Language (OEL)
Solution
What happens when an administrator deactivates a group rule?
When an administrator deactivates a group rule, Okta does not remove users that the rule added to a group. The group membership remains, but the rule no longer applies to new users. If an administrator reactivates the rule, Okta resumes assigning new users to the group based on the rule conditions.
Options presented when deleting a group rule.
When an administrator deletes a group rule, Okta displays a dialog box presenting the following two options for handling existing members that the rule added.
- Leave users in the group: Users remain members of the group, but the rule no longer manages the membership.
- Remove users from the group: Okta removes the users from the group entirely.
NOTE: The choice an administrator makes when deleting a group rule is permanent and irreversible.
