<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008S5n92SABOkta Classic EngineAdministrationAnswered2018-11-02T18:35:57.000Z2018-10-19T02:52:49.000Z2018-11-02T18:35:57.000Z

NelsonL.79519 (Customer) asked a question.

Deactivated User

Hi Support,

 

When On-premised Actove Directory users are removed from Okta it didn't deviated the account automatically until I have to performed a manual full import. Take note I have setup JIT with 1 hour interval sync.

 

Another question how can I perform a bulk deletion automatically for deactivate users.


  • Hello Nelson,

     

    That is the expected behavior, because unless you use Realtime Sync, only the next import will update the user data and reflect the AD status, which is set to 1 hour in your environment, in this case.

     

    Real-time sync updates user profiles, groups, and group memberships during sign-in instead of waiting for a scheduled import. You do not have to import all the users in your directory beforehand. Real-time sync also updates user information whenever you load or refresh a user's People page. See Using the Okta People page for more information. 

     

    https://help.okta.com/en/prod/Content/Topics/Directory/Directory_People.htm

     

    Administrators can change organizational units (OUs), user profile information, and group information in Active Directory (AD) and users are immediately updated.

     

    We currently do not have a bulk deletion option in the User Interface, but you can make use of the Okta API to automate user deletion.

     

    If you have any further questions or concerns, please open a ticket with support so we can better assist you.

     

     

     

    Thank you,

    Bogdan Andrisan

    Okta Customer Support

    Expand Post
    Selected as Best
  • Hello Nelson,

     

    That is the expected behavior, because unless you use Realtime Sync, only the next import will update the user data and reflect the AD status, which is set to 1 hour in your environment, in this case.

     

    Real-time sync updates user profiles, groups, and group memberships during sign-in instead of waiting for a scheduled import. You do not have to import all the users in your directory beforehand. Real-time sync also updates user information whenever you load or refresh a user's People page. See Using the Okta People page for more information. 

     

    https://help.okta.com/en/prod/Content/Topics/Directory/Directory_People.htm

     

    Administrators can change organizational units (OUs), user profile information, and group information in Active Directory (AD) and users are immediately updated.

     

    We currently do not have a bulk deletion option in the User Interface, but you can make use of the Okta API to automate user deletion.

     

    If you have any further questions or concerns, please open a ticket with support so we can better assist you.

     

     

     

    Thank you,

    Bogdan Andrisan

    Okta Customer Support

    Expand Post
    Selected as Best
  • NelsonL.79519 (Customer)

    Kindly advise how to activate real time sync, in your URL it didn't specifically tell how to achieve it. Thanks
  • NelsonL.79519 (Customer)

    Hi Support,

    I’m already using AD Agent 3.11 and above. Please advise the specific step to setup Realtime Sync,

    Regards
This question is closed.
Loading
Deactivated User