
ColtonA.85802 (Customer) asked a question.
I have a large number of users in a single OU and I wanted to know if there was a way to filter which users get synced with Okta based on the value of an Active Directory attribute. If this is not possible, is there a way to auto provision accounts for the users based on the AD attribute?

Yes it is possible. You will need to set the User Filter under Provisioning\Integration for your AD instance.
I recommend you first test the your LDAP filter before making changes using the built-in ldp.exe LDAP client on Windows servers. This is especially important if you are syncing more than one OU. The filter will apply to all OUs that are being synced.
Examples