Enable Okta-sourced user Organizational Unit updates

When an Okta-sourced user or a user sourced by a human resources application is added to an Okta group that provisions to Active Directory (AD), the matching AD user is automatically moved to the organizational unit (OU) to which the group provisions. Your organization can provision multiple groups to AD, and each of the groups can provision to a different OU.

When a user belongs to multiple groups, the group priority order determines which OU the user is added to. The group priority order is respected when a user is added to a group, and the OU doesn't always change.

  1. In the Admin Console, go to DirectoryDirectory Integrations.
  2. Click Active Directory, and then click the Provisioning tab.
  3. Click To App in the Filters list.
  4. Click Edit in the right pane.
  5. In the Update User Attributes area, select Update OU when the group that provisions a user to AD changes.
  6. Click Save.