<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00007Qb8LiSAJOkta Classic EngineLifecycle ManagementAnswered2026-04-01T09:00:20.000Z2020-01-02T20:22:45.000Z2020-01-08T20:25:17.000Z
Manage users in Okta

We deployed Okta into an environment with Active Directory (existing) and we have linked the AD groups with Okta groups. Our goal is to truly managed all users from Okta, to do this we are going to import all existing users in the AD groups into the Okta groups. Are there any issues with this approach?


  • t529b (t529b)

    After reading through the documentation, I think I understand what you mean now (although I'm not familiar with this feature, and I don't even see a Push Groups tab in the directory settings in my org, so it's probably not enabled). You linked new, empty Okta groups with AD groups that already have members, and you want the members of the AD groups to also show up in the Okta groups, so that the Okta groups accurately reflect the members of the AD groups.

     

    From what I've read (https://help.okta.com/en/prod/Content/Topics/Directory/group-push-enh.htm), you definitely want to add those users to the Okta groups. The doc indicates that Okta is the master in this configuration, which sounds like there's the potential for the agent to remove users from your AD groups if they don't exist in the linked Okta group. Again, I've never used this feature personally, so I could be way off the mark. Proceed with caution, and good luck!

    Expand Post
    Selected as Best
  • t529b (t529b)

    What do you mean by "linked the AD groups with Okta groups"? Did you deploy the Okta AD agent and configure the directory integration to import your AD users and groups?

    • Mike,

      Yes we configured the directory integration to import AD users and groups. Then we created Okta groups and linked them to the AD groups (Push Groups). Now we would like Okta to reflect all users in the groups (pre and post Okta implementation).
      Expand Post
  • Yes we configured the directory integration to import AD users and groups. Then we created Okta groups and linked them to the AD groups (Push Groups). Now we would like Okta to reflect all users in the groups (pre and post Okta implementation).

  • t529b (t529b)

    After reading through the documentation, I think I understand what you mean now (although I'm not familiar with this feature, and I don't even see a Push Groups tab in the directory settings in my org, so it's probably not enabled). You linked new, empty Okta groups with AD groups that already have members, and you want the members of the AD groups to also show up in the Okta groups, so that the Okta groups accurately reflect the members of the AD groups.

     

    From what I've read (https://help.okta.com/en/prod/Content/Topics/Directory/group-push-enh.htm), you definitely want to add those users to the Okta groups. The doc indicates that Okta is the master in this configuration, which sounds like there's the potential for the agent to remove users from your AD groups if they don't exist in the linked Okta group. Again, I've never used this feature personally, so I could be way off the mark. Proceed with caution, and good luck!

    Expand Post
    Selected as Best
This question is closed.
Loading
Manage users in Okta