
SurajB.69263 (Customer) asked a question.
understanding SYNC behavior for Org units (Okta <-> Google)
We have Google SCIM hooked up to our IDP Okta. We are trying to understand the behavior of OU’s and the mapping as some OU changes we make in Google stick and others revert back to original OU thats mapped in Okta.
We would like to know the sync behavior, when the syncs happen, and how to manually / automatically adjust these so we can manage OU’s through Okta vs making changes directly in Google (or vice versa) and have Okta update to match.

Hi @SurajB.69263 (Customer) , Thank you for reaching out to the Okta Community!
The core issue is that Okta's provisioning model is unidirectional by default: Okta pushes attributes to Google Workspace, not the other way around. When you make OU changes directly in Google Workspace, those changes are not automatically synced back to Okta. If Okta then performs a provisioning sync (either scheduled or manual), it will push the OU value stored in Okta's user profile back to Google Workspace, overwriting any changes you made directly in Google.
Root Cause:
Okta provisioning is designed as a push-only mechanism. The Google Workspace app in Okta's catalog provisions users and attributes from Okta to Google Workspace using SCIM. By default, Okta does not import or monitor changes made directly in Google Workspace—it only sends updates outbound. This means:
Solution:
To manage OUs consistently, you must choose a single source of truth and configure your provisioning accordingly:
Option 1: Manage OUs in Okta (Recommended for most organizations)
Option 2: Manage OUs in Google Workspace (Requires bidirectional sync setup)
If you need to manage OUs primarily in Google Workspace and have Okta reflect those changes, you must set up profile import or directory sync from Google Workspace back into Okta. This is not the default behavior and requires additional configuration:
Sync Frequency and Manual Triggers:
Best Practice:
Designate Okta as your authoritative source for OU management. This ensures consistency, prevents conflicts, and simplifies troubleshooting. If you need OU data to originate from Google Workspace, work with Okta Support to configure inbound profile import and set appropriate source priorities.
We hope this resolves the issue. If you need account-specific verification of your provisioning configuration or bidirectional sync capabilities, please contact Okta Support.
NOTE: If you are leveraging a custom SCIM implementation instead of the OIN catalog Google Workspace app implementation, please reach out to devforum.okta.com for clarification, as custom SCIM apps are their purview.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Just released: More Okta Community badges just added