<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000AYqWUiSQNOkta Classic EngineOkta Integration NetworkAnswered2024-04-16T11:15:24.000Z2021-03-02T18:38:46.000Z2021-03-10T16:32:33.000Z

emomo (emomo) asked a question.

Office365 Federation with current users and AD.

I have AADConnect(Dirsync) from my on prem DC that provisions users to 0365. I also have the OKTA agent on the same DC that uploads users to OKTA. I inherited this setup, if you are wondering.

 

I want to get rid of AADConnect and just use the OKTA agent. Can you please send me any documentation to match my OKTA users to their accounts in Office 365?

 

Thank you


  • ScottW.66567 (Customer)

    I'm also interested in this. I have the same set up and I need to push more attributes to O365 from Okta, but I can't since I have AADConnect and I'm limited to "profile sync" instead of "Universal Sync"

  • feok4 (feok4)

    There is some good documentation here - https://help.okta.com/en/prod/Content/Topics/Apps/Office365-Deployment/configure-sso.htm

     

    In re to AADC and Okta API, you need to disabled AADC before you can enable Okta provisioning. Also be mindful of profile sync, user sync and universal sync options - some are one way trips, requiring you to disable API integration before choose another options, i.e. can't go from universal sync to profile sync.

     

    Also me mindful of the deactivate users option - we keep this option unchecked as a precaution.

     

    Not sure if this answers your question - post back if needed.

    Expand Post
  • ScottW.66567 (Customer)

    Is there anything I need to be worried about when disabling AADC? The way I understand it is it syncs user accounts/passwords from AD -> O365. Enabling Universal Directory will allow Okta to create the O365 accounts.

    This will allow Okta to push to my on-prem to create accounts and O365 at the same time and since they will have the same UPN (or other unique identifier) the accounts will link together without an issue, correct?

    Expand Post
This question is closed.
Loading
Office365 Federation with current users and AD.