<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000019Oui80ACOkta Classic EngineDirectoriesAnswered2026-09-26T09:02:50.000Z2026-01-09T19:00:00.000Z2026-09-22T19:02:56.000Z

llq88 (llq88) asked a question.

Nested AD Groups and Okta; When the Nested Group Isn't Imported

I have an interesting scenario that I'd like to solicit input from the broader Okta admin community on. As the title suggests, I have a use case where an Active Directory group is in an OU being imported into Okta, which contains a nested AD group, but where the nested group is in an OU that is not being imported into Okta. The use case here being that our AD environment has loose groups in the top-level OU that must not be imported into Okta, thus preventing us from importing the top-level OU with those groups, but it also includes groups that would be worth having.

 

The solution we tried was to create the second group in an OU that was being imported, but Okta doesn't seem to be able to recognize the nested group. While we could schedule a task to replicate users into the second group with some automation on our local servers, I'd like to find something that future admins won't have to hunt for. Am I missing any options in Okta? Is there a way to import individual groups when the OU it is in isn't being imported? Moving the groups isn't an option because we know that there are some dependencies that require the OU's DistinguishedName remain the same. It seems like the legacy decisions of my org are boxing me into a corner, here.


  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    Okta cannot import a nested Active Directory (AD) group unless the Active Directory integration includes the organizational unit (OU) containing the nested group. To import a group, administrators must select the specific OU in the AD integration settings. Administrators attempting to import individual groups from unselected OUs will find that Okta does not recognize or import those groups.

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • Active Directory (AD)

    Solution

    Okta requires the organizational unit selection to import individual Active Directory groups.

    At this time, Okta does not support importing an individual group without an organizational unit (OU) selection. To import a group into Okta from Active Directory, administrators must select the OU containing the group in the Import section.

    How does the Okta Active Directory integration exclude unwanted groups when importing a top-level organizational unit?

    As an alternative, select the top-level OU for import and utilize the group and user filtering features within the Okta Active Directory integration. This allows Okta to import the required nested groups while excluding specific groups in the top-level OU.

    Related References

     

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @llq88 (llq88)​ Thank you for posting on our Community page!

     

    At this time this is not possible, in order to import a group into Okta from AD the OU they are a part of needs to be selected in the import section.

    You can check our doc on how we handle Nested groups below:

    https://support.okta.com/help/s/article/How-does-Okta-handle-nested-groups?language=en_US

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Join the discussion for our Ask Me Anything on January 20, 2026: Adoption of Stronger Authentication MFA. Ask our expert questions.

    Expand Post
  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    Okta cannot import a nested Active Directory (AD) group unless the Active Directory integration includes the organizational unit (OU) containing the nested group. To import a group, administrators must select the specific OU in the AD integration settings. Administrators attempting to import individual groups from unselected OUs will find that Okta does not recognize or import those groups.

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • Active Directory (AD)

    Solution

    Okta requires the organizational unit selection to import individual Active Directory groups.

    At this time, Okta does not support importing an individual group without an organizational unit (OU) selection. To import a group into Okta from Active Directory, administrators must select the OU containing the group in the Import section.

    How does the Okta Active Directory integration exclude unwanted groups when importing a top-level organizational unit?

    As an alternative, select the top-level OU for import and utilize the group and user filtering features within the Okta Active Directory integration. This allows Okta to import the required nested groups while excluding specific groups in the top-level OU.

    Related References

     

    Expand Post
    Selected as Best
This question is closed.
Loading
Nested AD Groups and Okta; When the Nested Group Isn't Imported