<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006dq4A6SAIOkta Classic EngineAdministrationAnswered2024-04-16T11:15:24.000Z2019-09-09T21:36:40.000Z2019-09-10T19:15:22.000Z
Syncing accounts between multiple disconnected forests.

​Have a use case to sync accounts between multiple AD forests. We have separate forests for dev/test/prod and a few others. The use case is similar to the following:

 

1) Provision user John in Prod AD.

2) Add user John to Dev group in Prod AD.

3) Account for John gets created in Dev AD and password synced.

4) John goes to Dev and uses the same credentials to access.


  • feok4 (feok4)

    Is this a question or statement? You can multiple forests connected to a single Okta org using agents in each forest. I would caution you to keep the UPNs unique. We've done this with 6 separate forests into a single Okta org (we didn't use p/w sync).

  • I guess there is some process I am missing then.

     

    I want the admins in forest one to add AD users to AD groups and have Okta respond to that change by creating users in other forests. So if John is in the prod AD and becomes a member of the DEV group in AD, Okta should create a user account for john in the DEV AD forest. ​

    Expand Post
This question is closed.
Loading
Syncing accounts between multiple disconnected forests.