
k5pob (k5pob) asked a question.
When a Active Directory user is imported to OKTA, and disconnected from AD, the disconnected user is dropped from all the AD groups that the user was in previously.
Is there a way that OKTA does not drop the existing AD groups after disconnecting user profile with AD.

Hello @k5pob (k5pob) Thank you for reacting out to our Community!
This is expected behaviour, as the user needs to be connected to AD to have access to the AD groups. Since the user is disconnected from AD, he does not have access to them anymore.
Community members help others by clicking Like or Select as Best on responses. Try it today.
Earn Today: New Okta Community Badges Have Arrived
Thank you for the response @paul.stiniguta1.508386743840768E12 (Okta, Inc.) .
How can we add users back to those okta imported AD groups. Currently OKTA is not allowing to assign imported AD groups to those AD disconnected users and vice versa.
Thank you for the response.
How can we add users back to those okta imported AD groups. Currently OKTA is not allowing to assign imported AD groups to those AD disconnected users and vice versa.
Unfortunately, there is no way. What you can do as a workaround, you can create a group with the same name and create a group rule to assign users that are in the AD group to the Okta group.
Please see our doc about this here : https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-about-group-rules.htm
Community members help others by clicking Like or Select as Best on responses. Try it today.
Earn Today: New Okta Community Badges Have Arrived