Import Users from AD to Okta

0.0(0)
studied byStudied by 0 people
0.0(0)
linked notesView linked note
full-widthCall with Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/40

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No study sessions yet.

41 Terms

1
New cards

What happens to new AD users during Okta import?

New AD users are created in Okta.

2
New cards

How does Okta handle modified AD users during import?

Modified AD users are updated in Okta.

3
New cards

What occurs in Okta when an AD user is disabled?

The disabled AD user is deactivated in Okta.

4
New cards

What is synced to Okta when there are changes in AD Group/OUs?

Changes are synced to Okta.

5
New cards

What are the matching criteria used to determine if an AD user exists in Okta?

Matching can be based on Okta username, email, a single attribute (like SAMAccountName), or multiple attributes.

6
New cards

What happens when there is an exact match with an existing Okta user during import?

The first name updates to the AD name since AD is the source of truth.

7
New cards

What is the risk of using partial matching during import?

Partial matching is not recommended due to the risk of merging different people.

8
New cards

What types of users can be confirmed during AD import in Okta?

Matched users and new users can be confirmed.

9
New cards

What can you do to disable activation emails during Okta provisioning?

Go to Provisioning → To Okta and select 'Don't send new user activation emails'.

10
New cards

When should you choose Import over JIT provisioning?

Use Import when you want predictable scheduled user sync, need to confirm matches, want staged rollouts, or require full group imports before login.

11
New cards

When is JIT provisioning preferred over manual import?

Choose JIT when accounts should only be created at first login, real-time updates are necessary, or scheduled imports are not desired.

12
New cards

How are scheduled imports defined in Okta?

Scheduled imports run automatically at defined intervals and are incremental, syncing only users changed since the last import.

13
New cards

What is the main difference between manual and scheduled imports?

Manual imports can be triggered at any time, whereas scheduled imports run at regular intervals automatically.

14
New cards
ad_import_deck = """
15
New cards
What does importing from AD do for new users?
Creates new Okta users for new AD users.
16
New cards
What does importing from AD do for modified users?
Updates existing Okta users based on AD changes.
17
New cards
What happens when an AD user is disabled?
They are deactivated in Okta.
18
New cards
Do AD group and OU changes sync to Okta?
Yes they are reflected in Okta during import.
19
New cards
What determines whether AD user becomes new or matched in Okta?
Matching criteria.
20
New cards
What attributes can matching criteria use?
Okta username email SAMAccountName or multiple attributes.
21
New cards
What is an exact match?
When the selected matching attribute(s) match between AD user and Okta user.
22
New cards
Does an exact match require identical first names?
No matches can occur even if names differ as long as the match attribute matches.
23
New cards
What happens after confirming an exact match?
Mapped Okta attributes update with AD values.
24
New cards
What is a partial match?
Match based only on first and last name.
25
New cards
Why are partial matches not recommended?
They may accidentally merge users with identical names.
26
New cards
Should auto-confirm partial matches be enabled?
No always confirm partial matches manually.
27
New cards
What does auto-confirm exact matches do?
Automatically confirms users whose attributes match according to criteria.
28
New cards
When should auto-confirm exact matches be turned on?
After confirming matching rules work correctly.
29
New cards
What does auto-confirm new users do?
Automatically confirms new users created from import.
30
New cards
What does auto-activate new users do?
Automatically activates new Okta accounts after import.
31
New cards
When should auto-activate new users be enabled?
After initial rollout once processes are stable.
32
New cards
What is the effect of activating a user by default?
Sends the user an activation email.
33
New cards
How do you disable activation emails for AD imports?
Provisioning → To Okta → Check “Don’t send new user activation emails for this domain”.
34
New cards
Should you import users when using JIT?
No choose Skip users during import.
35
New cards
What is a manual import?
An admin-triggered on-demand import of users and groups.
36
New cards
What is a scheduled import?
An automated periodic incremental import of changed or new AD users.
37
New cards
What does an incremental import do?
Imports only users created or updated since the last import.
38
New cards
When is importing preferred over JIT?
When you want predictable sync confirmations staged rollouts or full group imports before login.
39
New cards
When is JIT preferred over importing?
When you want real-time creation and updates at first login with no scheduled imports.
40
New cards
"""
41
New cards