<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000019Oui80ACOkta Classic EngineDirectoriesAnswered2026-01-22T02:56:07.000Z2026-01-09T19:00:00.000Z2026-01-22T02:56:07.000Z

PhoenixB.21381 (Customer) asked a question.

Nested AD Groups and Okta; When the Nested Group Isn't Imported

I have an interesting scenario that I'd like to solicit input from the broader Okta admin community on. As the title suggests, I have a use case where an Active Directory group is in an OU being imported into Okta, which contains a nested AD group, but where the nested group is in an OU that is not being imported into Okta. The use case here being that our AD environment has loose groups in the top-level OU that must not be imported into Okta, thus preventing us from importing the top-level OU with those groups, but it also includes groups that would be worth having.

 

The solution we tried was to create the second group in an OU that was being imported, but Okta doesn't seem to be able to recognize the nested group. While we could schedule a task to replicate users into the second group with some automation on our local servers, I'd like to find something that future admins won't have to hunt for. Am I missing any options in Okta? Is there a way to import individual groups when the OU it is in isn't being imported? Moving the groups isn't an option because we know that there are some dependencies that require the OU's DistinguishedName remain the same. It seems like the legacy decisions of my org are boxing me into a corner, here.


Loading
Nested AD Groups and Okta; When the Nested Group Isn't Imported