
iq96g (iq96g) asked a question.
We are using Okta to control which OUs users are assigned in Active directory. But to do so we have to convert individual assignments to group assignments. Is there an easier way to do it rather than unassigning the individual then assigning them to a group?

Yes! I would recommend tying the specific group to a directory location (i.e. your OU), then just adding the user to that group. It would automatically provision them to AD and in the correct location. It can be an Okta or Workday group, for example. How to Populate an Okta Group with Users from an Active Directory OU
Push groups may work for your use case as well, depending on what you need. Configure enhanced group push for Active Directory organizational units
Hope these links help! Thanks!
The groups are already tired to an OU but we need to convert our users from induvial assignments to the AD app to groups assignments so it actually moves the users to the OU.
Thanks!
This link talks about that as well:
https://support.okta.com/help/s/question/0D50Z00008C3jXbSAJ/add-okta-user-to-active-directory-group?language=en_US
the first link i provided is less about provisioning to AD, so that may not be the best one. I would recommend the above bullet.
Hi @iq96g (iq96g) , Thank you for reaching out to the Okta Community!
Assuming I understood the use case correctly and you are not talking about group memberships (Push Groups), this article goes over the configuration steps required to provision users to the downstream AD integration.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Subscribe Today: The Okta Community is on YouTube
We already have this set up. I just want to know the best way to convert the Active directory assignments from individual to group assignments so the OU groups actually move people.
Thanks!
Any User provisioning from Okta to AD would have to go through the designated Okta Group(s) - Manage Directories function and would show the user listed under the Directory Integration/AD/Assignments tab as type “Group” .
The fact that you mentioned the users as being listed as “individual” , would suggest that they were imported from AD to Okta.
While the UI might be similar to generic provisioning enabled apps, functionally, the AD integration works a bit different. I’m not aware of any Convert Assignment functionality for AD integrations.
Ideally, you would have to settle for unidirectional user management to avoid conflicts and misalignment.
If you have a test/preview environment where you can try it out, you could look into assigning the “individual” users to the Okta group(s) with which you manage the others.
If you only have a Production environment, I recommend opening a case so one of my Support Team colleagues can have a look at your implementation.
Regards.
--------------------------------
Subscribe Today: The Okta Community is on YouTube