<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000A45Es0CQEOkta Classic EngineDirectoriesAnswered2024-05-03T19:59:51.000Z2024-03-24T21:25:21.000Z2024-04-01T14:39:21.000Z

Issac Brumer (Customer) asked a question.

Retrieve only not deprovisioned users from LDAP interface

Hello: I'm trying to pull user accounts from the LDAP interface (not LDAP integration) to exclude deprovisioned accounts. The Okta documentation does not appear to include mention of how to filter on status. What is the appropriate filter for status? Thanks,


  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @Issac Brumer (Customer)​ 

     

    Thank you for posting on our Community page!

     

    Here is some info on LDAP troubleshooting:

    https://help.okta.com/en-us/content/topics/directory/ldap-troubleshooting.htm

     

    Temporarily segregate inactive LDAP accounts

    If you don’t want to perform an import because your LDAP directory contains many inactive user accounts, you can perform the following workaround to identify likely inactive accounts and segregate them before you import:

    1. Run a query against your LDAP directory for the attribute lastlogon (or another attribute that filters for inactive accounts).
    2. Move the inactive user objects out of their synchronization container to ensure they aren't introduced into Okta during import. You can move these objects back in after the import is finished.

     

    My advice would be to leverage the Okta Developer forums for this type of questions and take advantage of their expertise.

    https://devforum.okta.com/

     

    Thank you for reaching out to our Community and have a great day!

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @Issac Brumer (Customer)​ 

     

    Thank you for posting on our Community page!

     

    Here is some info on LDAP troubleshooting:

    https://help.okta.com/en-us/content/topics/directory/ldap-troubleshooting.htm

     

    Temporarily segregate inactive LDAP accounts

    If you don’t want to perform an import because your LDAP directory contains many inactive user accounts, you can perform the following workaround to identify likely inactive accounts and segregate them before you import:

    1. Run a query against your LDAP directory for the attribute lastlogon (or another attribute that filters for inactive accounts).
    2. Move the inactive user objects out of their synchronization container to ensure they aren't introduced into Okta during import. You can move these objects back in after the import is finished.

     

    My advice would be to leverage the Okta Developer forums for this type of questions and take advantage of their expertise.

    https://devforum.okta.com/

     

    Thank you for reaching out to our Community and have a great day!

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
This question is closed.
Loading
Retrieve only not deprovisioned users from LDAP interface