<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008Fdo5ESAROkta Classic EngineAnswered2025-06-14T10:27:26.000Z2018-08-14T17:21:25.000Z2018-10-12T19:29:45.000Z

2a4bz (2a4bz) asked a question.

When integrating AD does the initial load activate users? If so how do you prevent this?

When you first integrate AD to Okta, and you activate the Agent..what happens? Since it is a preview environment I don't want to load 70,000 AD users and activate them. How do I just add one at a time at this point in the installation? What is a AD scan versus an AD load?


  • Thanks for reaching out to the Support Community today!

     

    When integrating AD with Okta which requires installing the AD Agent and configuring the Active Directory settings in your Okta Admin tenant, an AD Import is required to be trigged in order to bring user and group objects into Okta. What happens upon import is all dependent on the settings that are configured under Directory >> Directory Integrations >> Active Directory >> Settings tab. Okta will only pull in User and Group objects based on the OUs that you have selected under the User and Group OUs Connected to Okta section

     

    If you'd only like to Import users one at a time you have two options:

    • Option 1: Under the Confirmation Settings, ensure none of the auto-confirm or auto-activate setting options have been selected >> Run an AD Import >> Confirm new users manually on the Import tab
    • Option 2: Move the users you wish to import to a separate OU and only have this user OU set to sync with Okta >> Run an AD Import >> Confirm new users manually, or configure the Import match and confirmation settings to auto-confirm newly imported accounts

     

    When an Import is triggered in Okta for the first time, all Users and Groups into Okta based on the OUs you have selected to sync will be loaded in Okta. For all subsequent Imports, if there are no changes detected from the previous import, 0 users and groups will be scanned. Otherwise, if any user or group objects have changed from the previous import, only those objects will be scanned by the AD Agent and updated accordingly in Okta.

     

    The following articles provide a detailed description of each of the configurable Active Directory settings:

     

    https://help.okta.com/en/prod/Content/Topics/Directory/okta-active-directory-agent.htm?Highlight=attribute%20level%20mastering

     

    https://support.okta.com/help/s/article/Okta-AD-Agent

     

    Thank you,

     

    Aleks Bulajic

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
    Selected as Best
  • Thanks for reaching out to the Support Community today!

     

    When integrating AD with Okta which requires installing the AD Agent and configuring the Active Directory settings in your Okta Admin tenant, an AD Import is required to be trigged in order to bring user and group objects into Okta. What happens upon import is all dependent on the settings that are configured under Directory >> Directory Integrations >> Active Directory >> Settings tab. Okta will only pull in User and Group objects based on the OUs that you have selected under the User and Group OUs Connected to Okta section

     

    If you'd only like to Import users one at a time you have two options:

    • Option 1: Under the Confirmation Settings, ensure none of the auto-confirm or auto-activate setting options have been selected >> Run an AD Import >> Confirm new users manually on the Import tab
    • Option 2: Move the users you wish to import to a separate OU and only have this user OU set to sync with Okta >> Run an AD Import >> Confirm new users manually, or configure the Import match and confirmation settings to auto-confirm newly imported accounts

     

    When an Import is triggered in Okta for the first time, all Users and Groups into Okta based on the OUs you have selected to sync will be loaded in Okta. For all subsequent Imports, if there are no changes detected from the previous import, 0 users and groups will be scanned. Otherwise, if any user or group objects have changed from the previous import, only those objects will be scanned by the AD Agent and updated accordingly in Okta.

     

    The following articles provide a detailed description of each of the configurable Active Directory settings:

     

    https://help.okta.com/en/prod/Content/Topics/Directory/okta-active-directory-agent.htm?Highlight=attribute%20level%20mastering

     

    https://support.okta.com/help/s/article/Okta-AD-Agent

     

    Thank you,

     

    Aleks Bulajic

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
    Selected as Best
This question is closed.
Loading
When integrating AD does the initial load activate users? If so how do you prevent this?