
GiridharanD.41770 (Customer) asked a question.
Hi, Application access is controlled via AD groups which are assigned via okta, when an account is deactivated in okta, deactivated user should be removed from all AD groups. Can see an Idea (106829) opened for more than a year, is there any workaround to achieve this use case.
Thanks.

Can't think of a workaround via Okta.
However, you can have an external daily job setup to see which accounts are deactivated and then trigger the removal directly from AD groups.