<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008LSMXSCA5Okta Classic EngineDirectoriesAnswered2024-04-17T09:12:53.000Z2022-11-05T14:00:34.000Z2022-11-07T21:24:03.000Z

gh94t (gh94t) asked a question.

I have pushed a Group to Active Directory, but users are not syncing.

AD integration and Agent installed. I have enabled provisioning as per the procedure and pushed the group, but the users are still not syncing. What should I check?

 


  • 953nz (953nz)

    Few things to keep in mind when using Group Push:

     

    • Users shown as inactive are not pushed, they must be reactivated first then re-push the group. If the inactive user is part of more than one group, they must be re-pushed to all groups in which they are members.
    • do not make changes from the target app to the group (i.e. in this case do not modify memberships in the group from AD side - Okta only). "Making changes to the group in the target app causes synchronization issues with Okta."
    • Using the same Okta group for assignments and for group push is not supported. To maintain consistent group membership between Okta and the downstream app, you need to create a separate group that is configured to push groups to the target app.
    • You must have provisioning enabled in the target app. If it is not enabled, you will be prompted to do so (based on your description, this should be complete).
    • Any group members that you want to push to the target app MUST be previously provisioned and assigned to the target app. As an Okta-sourced group, changes should never be made from the target app.
    • Confirm that the relevant group members are already imported into Okta and provisioned for the target app.
    • To push groups to Active Directory, you must have permission to create groups in Active Directory. See About Okta service account permissions.

     

    Ultimately, ensure the above is all complete to the best of your ability. Finally, do check under "Directory Integrations" > "Provisioning" > "Integration" and ensure that under "Import Settings" you have the OU/Sub-OU selected for wherever you are attempting to push as well (User OUs/Group OUs)

     

    Finally, note that when you utilize "Push Now" the following to be true: "When this option is selected for Active Directory, only the newest members are pushed to the group and memberships are not overwritten."

     

    There is a lot I spat out here, but you can find the majority of the source material here Manage Group Push

     

    Thanks! Please let us all know how things turn out.

    Expand Post
  • mugl8 (mugl8)

    You will need to link the group with an AD OU. Once you create the Okta Group > Click on the Group Name > Go to the "Directories" tab > Click on "Manage Directories" > Choose the OU where you are pushing data from Okta to AD. And then activate the Push group again.

This question is closed.
Loading
I have pushed a Group to Active Directory, but users are not syncing.