
i0i4e (i0i4e) asked a question.
Okta has great rules for adding users to groups, but there's no rules to REMOVE a user from a group. Ex. if a user's Department ISN'T Sales or DOES NOT CONTAIN Marketing, remove them from the group.
My organization is organizing users by Groups, and when users are moving between departments, we need to automate group moves. It is easy enough to add the user to their new group via automation, but impossible to remove them from their old group, from what I see. I'd automate this through Google, but even with Enhanced Push, Google's group membership doesn't sync back to Okta Groups.

Hi Bobby,
As far as I'm aware not even Okta LCM can handle that. It can only remove from groups Okta had already added the user to. For full deprovisioning I'm 90% you'll need to rely on Event Hooks and possibly PowerShell, AD Manager or some other AD scripting. I say 90% because I sure don't know everything and I asked this question to the Okta Sales Engineer prior to our purchase and this is what was suggested.