
SurajB.69263 (Customer) asked a question.
understanding SYNC behavior for Org units (Okta <-> Google)
Thanks for the very detailed response! earlier case here is the previous case (https://support.okta.com/help/s/question/0D5WR000026zdd60AA/understanding-sync-behavior-for-org-units-okta-google?language=en_US), However This does not match what we see in Okta / Google. Im betting some of this is based on when the Okta / Google integration was configured but our ultimate goal is to be able to manage the OU’s in Google without Okta overwriting it and have Okta just provision access and handle push groups as needed.
When we look in Okta under the provisioning settings here is what we see. This looks to contradict your note above. The attribute for the bidrectional sync is set to / (and my understanding is that means the top level OU in Google)
However notice the sceenshot of the end user, it has the / denoted in here app variables but in Google Admin she is in a differnt OU and has been there for much longer than 12 hours.
the image are in the link as not bale to add the image https://drive.google.com/drive/folders/1wfBIc6HiF7Ptm15m1nTBxTEEBg0UuURN

Hello @SurajB.69263 (Customer) Thank you for posting on our Community page!
The issue is that the "/" attribute in your provisioning settings is likely a default or fallback value, not an active inbound sync from Google Workspace. Even though Okta supports bidirectional attribute mapping in the Profile Editor, the presence of a mapping does not guarantee that profile import is actively running or that it is correctly pulling the OU attribute from Google Workspace back into Okta.
Root Cause:
Okta's provisioning model has two separate mechanisms:
The "/" value you see in the app variables is likely the default or initial value that was set when the user was first provisioned to Google Workspace. If inbound profile import is not actively running, or if it is not configured to prioritize Google Workspace as the source for the OU attribute, Okta will not pull the user's current OU from Google Workspace back into Okta's profile.
Solution:
To manage OUs in Google Workspace and have Okta reflect those changes, you must verify and configure inbound profile import:
Important: The behavior you are observing—where the app variables show "/" but the user is in a different OU in Google Workspace—suggests that inbound profile import may not be actively pulling the OU attribute. Verify the steps above, and if the issue persists, escalate to Okta Support for account-specific troubleshooting.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.