AD Attribute Still in Okta Profile after Removing Mapping
Last Updated:
Overview
Applies To
- Directories
- Attribute
- Profile Editor
- Mapping
Cause
Okta only changes an existing attribute value if there is an update to the value. If the attribute is unmapped in Profile Editor, it will not remove the attribute's value from existing profiles.
Solution
Instead of unmapping an attribute to remove its value from existing profiles, map the attribute to Null by mapping it to two quotation marks without a space in between - "".
NOTE: These steps do not apply to the user.secondEmail attribute, as this attribute can only be updated with an actual email address and not with a null value.
-
In the Okta Admin Dashboard, select Directory > Profile Editor, select Directories in the middle, and select Mappings next to the directory where the change is required.
-
Find the Okta attribute in the right column, add two quotation marks without a space to the box in the left, click the dropdown in the middle, and select Save Mappings.
-
Select Apply updates now, and the null value will push to all Okta profiles that belong to that Directory.
