<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008dka1LSAQOkta Classic EngineUniversal DirectoryAnswered2018-12-03T22:25:22.000Z2018-11-28T02:24:24.000Z2018-12-03T22:25:22.000Z
  • Hello,

     

    Thank you for reaching out to Okta Community! The "Access is denied" message typically indicates a permission issue of the service account in AD. Is the service account used to run your Okta AD Agent a domain admin? If not, then as a troubleshooting step, I recommend trying to make it a domain admin and retry the group push. If successful, this will confirm a permissions issue. When sending the users downstream from Okta to AD, we need to make sure that the service account has read and write permissions. 

     

    Please review the "Okta service account permissions" section in our AD configuration documentation for more details, linked here: https://help.okta.com/en/prod/Content/Topics/Directory/ad-agent-install.htm#OktaService

     

    "Okta service account permissions

    The AD agent runs under the Okta account you specified (either the Okta service account the installer creates or the domain user you select during the agent install). Depending on the configuration of your integration, the agent performs the following actions:

    • Read users, OUs, and groups — Requires read access on the accessed objects. By default, a domain user has sufficient permission to do this. We recommend read access on the entire domain, but it is not required.
    • Authenticate users — No special permissions are required.
    • Change user passwords (by supplying the current password) — No special permissions are required.
    • Set user passwords (administratively, without the current password) — Requires permissions to set passwords for users.
    • Create and update users, attributes, and memberships in AD with values pushed from Okta — Requires permissions to read and write to the attribute(s) you are updating."

     

    Alternately, can you confirm the service account has permissions on the OU you're pushing the group to? If the above troubleshooting steps didn't resolve the issue, please feel free to open a case with Support so we can look into your AD configurations. 

     

    Thanks,

     

    Daisy Sun

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
This question is closed.
Loading
Push group error: Access denied!