<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

AD Attribute Still in Okta Profile after Removing Mapping

Directories

Overview

This article explains why removing a mapping between an Active Directory (AD)/LDAP profile and an Okta profile does not remove the attribute value from an existing user's profile. The steps from this article also apply to any other Profile Source. 

Applies To

  • Directories
  • Attribute
  • Profile Editor
  • Mapping

Cause

Okta only changes an existing attribute value if there is an update to the value. If the attribute is unmapped in Profile Editor, it will not remove the attribute's value from existing profiles.

Solution

Instead of unmapping an attribute to remove its value from existing profiles, map the attribute to Null by mapping it to two quotation marks without a space in between - "".

NOTE: These steps do not apply to the user.secondEmail attribute, as this attribute can only be updated with an actual email address and not with a null value.

 
Please follow the video or the steps below: 
  1. In the Okta Admin Dashboard, select Directory > Profile Editor, select Directories in the middle, and select Mappings next to the directory where the change is required.
    Profile Editor 

  2. Find the Okta attribute in the right column, add two quotation marks without a space to the box in the left, click the dropdown in the middle, and select Save Mappings.
    Attribute mapping 

  3. Select Apply updates now, and the null value will push to all Okta profiles that belong to that Directory.
    "Apply updates now" button 

 
Loading
Okta Support - AD Attribute Still in Okta Profile after Removing Mapping