<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000AJPO5eCQHOkta Classic EngineDirectoriesAnswered2025-01-23T17:20:36.000Z2025-01-22T17:46:02.000Z2025-01-23T17:20:36.000Z

DavidB.84594 (Customer) asked a question.

multiple Active Directories connected and I need to remove one.

If I remove an AD connection, will all those users automatically be Okta sourced users. Or do I have to loop through all the users first to make them Okta sourced, then remove the AD connection?


  • MatthewH.10249 (State of Iowa)

    I cannot locate any documentation that says specifically but the following docs make it sound to me like they would switch to Okta sourced but I could be wrong. If you don't get additional feedback on this community post I suggest you reach out to your Okta CSM and have them get in touch with techs from Okta to help you make the right changes to avoid issues.

     

    The following notes are mentioned in the first post link talk about things you should do before deactivating an Directory Integration. You also need to consider options to deal with passwords mentioned in the second post link below.

     

    https://support.okta.com/help/s/article/Deactivate-and-Delete-Active-Directory-Integrations?language=en_US

    "NOTE: Before deactivating a directory in Okta, be sure that: 

    • The directory is not set to source Okta users.
    • Update and Disable users options are disabled.
    • Delegated Authentication is disabled.
    • All connected users have Okta passwords.

    Okta Support cannot assist with major infrastructure changes like this. Please reach out to the assigned Account Executive to engage consulting services for this type of action."

     

    https://support.okta.com/help/s/article/How-to-disable-Delegated-Authentication-for-Active-Directory?language=en_US

    "When disabling Delegated Authentication, two options are presented: 1. Create an Okta password (recommended). 2. Do not create an Okta password"

    Expand Post
  • Mihai N. (Okta, Inc.)

    Hi @DavidB.84594 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    It depends on what kind of AD integration you are referring to with "multiple Active Directories".  

    If you are referring to a single domain integrated with Okta which uses multiple AD Agents for the connection and you are planning on removing one of connected servers/agents, then redundancy should kick in and the integration remains as is. Okta would just continue using the remaining agent(s).  

     

    If you are referring to multiple domain integrations with a single agent each... 

    Example: 

    AD-Domain1 (AcmeCompany.com) with Okta-AD-Agent1

    AD-Domain2 (CookieCompany.com) with Okta-AD-Agent2

    The integrations are separate entities, and if for example you deactivate the AD integration for domain AcmeCompany.com , you will get a prompt like this: 

    DeactivateMeaning that all users associated with AcmeDomain.com will be impacted by the deactivation, while there would not be any change for the CookieCompany.com ones.

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Join the discussion for Ask Me Anything on February 4, 2025: Advancements in Okta’s On-Prem Directory Integrations

    Expand Post
This question is closed.
Loading
multiple Active Directories connected and I need to remove one.