<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009uJFc8CAGOkta Classic EngineIntegrationsAnswered2025-04-14T09:00:37.000Z2023-12-18T15:47:05.000Z2023-12-19T19:09:49.000Z

k5pob (k5pob) asked a question.

Is there a way that OKTA does not drop the existing AD groups after disconnecting user profile with AD

When a Active Directory user is imported to OKTA, and disconnected from AD, the disconnected user is dropped from all the AD groups that the user was in previously.

Is there a way that OKTA does not drop the existing AD groups after disconnecting user profile with AD.


  • Paul S. (Okta, Inc.)

    Hello @k5pob (k5pob)​ Thank you for reacting out to our Community!

     

    This is expected behaviour, as the user needs to be connected to AD to have access to the AD groups. Since the user is disconnected from AD, he does not have access to them anymore.

     

    Community members help others by clicking Like or Select as Best on responses. Try it today.

     

    Earn Today: New Okta Community Badges Have Arrived

    Expand Post
    • k5pob (k5pob)

      Thank you for the response @Paul S. (Okta, Inc.)​ .

      How can we add users back to those okta imported AD groups. Currently OKTA is not allowing to assign imported AD groups to those AD disconnected users and vice versa.

  • k5pob (k5pob)

    Thank you for the response.

    How can we add users back to those okta imported AD groups. Currently OKTA is not allowing to assign imported AD groups to those AD disconnected users and vice versa.

This question is closed.
Loading
Is there a way that OKTA does not drop the existing AD groups after disconnecting user profile with AD