
b9vx3 (b9vx3) asked a question.
This isn't a new issue for us, but I figured I'd reach out and see if anyone ideas on how to bring some sanity back to our environment
We have four copies of almost all of our AD groups. One of the copies shows the on-prem AD icon, while the other three show the O365 icon. How do I tell where these groups came from and remove the copies that we don't need/want?

Hi Scott, when Office365 Provisioning is enabled all Office365 groups are imported into Okta by default.
The 3 groups that you see are imported from Office365 and they can only be remove from there but this is not recommended.This is just a visual thing and you can just work around them.Importing app groups in Okta when Provisioning is enabled was introduced recently and it is a group feature improvement.
Costel,
If provisioning is enabled on both AD and O365, then the issue is that only one of the four groups is correct. Adding someone to one of the other three groups doesn't write them back into the appropriate directory. If it was just a visual issue, it would be one thing, but since none of the copies work it requires a lot of "tribal knowledge" within the admin team to keep track of which group is the correct one.
When you say that importing app groups was introduced recently, does that mean that there is a feature that could help clean this up that's available now?