Import group owner information from Active Directory

This is an Early Access feature for orgs with Identity Governance enabled. Use the Early Access Feature Manager as described in Manage Early Access and Beta features to enable the feature.

Admins can now import the group ownership information from the Active Directory(AD) to Okta Directory using full or incremental imports. The system uses the managedBy attribute in AD user profile to extract the group owner information.

AD can have only one owner for a group, either a group or a user, so the imported group can also have only one owner.

View and assign ownership of an Active Directory instance

  1. In the Admin Console, go to Directory Groups.

  2. Select a group to open the Group page.

  3. Go to the Owners tab on the Group page. You can see the group owners for the group on this tab.

  4. Enable Group Ownership for Okta Directory to allow owner management from the Okta Directory.

  5. Enable Group Ownership sourced from Active Directory to import the group owner information using the managedBy attribute of the AD group.

Run a full or an incremental import afterward to get the group ownership information. The group won't have the owner information in Okta Directory, if the group owner information isn't available at the time of the import.

Related topics

Examples of Okta Expression Language