
llq88 (llq88) asked a question.
Nested AD Groups and Okta; When the Nested Group Isn't Imported
I have an interesting scenario that I'd like to solicit input from the broader Okta admin community on. As the title suggests, I have a use case where an Active Directory group is in an OU being imported into Okta, which contains a nested AD group, but where the nested group is in an OU that is not being imported into Okta. The use case here being that our AD environment has loose groups in the top-level OU that must not be imported into Okta, thus preventing us from importing the top-level OU with those groups, but it also includes groups that would be worth having.
The solution we tried was to create the second group in an OU that was being imported, but Okta doesn't seem to be able to recognize the nested group. While we could schedule a task to replicate users into the second group with some automation on our local servers, I'd like to find something that future admins won't have to hunt for. Am I missing any options in Okta? Is there a way to import individual groups when the OU it is in isn't being imported? Moving the groups isn't an option because we know that there are some dependencies that require the OU's DistinguishedName remain the same. It seems like the legacy decisions of my org are boxing me into a corner, here.

Updating this response for ease of access and reference:
Okta cannot import a nested Active Directory (AD) group unless the Active Directory integration includes the organizational unit (OU) containing the nested group. To import a group, administrators must select the specific OU in the AD integration settings. Administrators attempting to import individual groups from unselected OUs will find that Okta does not recognize or import those groups.
Applies To
Solution
Okta requires the organizational unit selection to import individual Active Directory groups.
At this time, Okta does not support importing an individual group without an organizational unit (OU) selection. To import a group into Okta from Active Directory, administrators must select the OU containing the group in the Import section.
How does the Okta Active Directory integration exclude unwanted groups when importing a top-level organizational unit?
As an alternative, select the top-level OU for import and utilize the group and user filtering features within the Okta Active Directory integration. This allows Okta to import the required nested groups while excluding specific groups in the top-level OU.
Related References