<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
AWS IAM Identity Center - Group push mapping for the group could not take effect due to error: Error while creating user group: Unauthorized
Lifecycle Management
Okta Integration Network
Okta Classic Engine
Okta Identity Engine
Overview

AWS IAM Identity Center group push is failing with the following errors visible in the Okta system log:

Changes to the Group push mapping for the group <group> could not take effect due to error: Error while creating user group <group>: Unauthorized

Changes to the Group push mapping for the group<group> could not take effect due to error: Error while trying to get the group <group> with the externalId <externalID> and id com.saasure.db.dto.platform.entity.AppGroup@3d94a15b[status=ACTIVE,name=<name>,description=<description>,externalId=<externalID>,appInstanceId=<appInstanceID>,userGroupId=<userGroupID>,oktaMastered=true,pushed=false,changeStatus=<null>,data=<null>,objectClass=,externalIdAndInstanceKey=<externalIDAndInstanceKey>,objectClassList=[]]: Unauthorized

 

System log

Applies To
  • AWS IAM Identity Center
  • Provisioning
  • Group Push
Cause

The API token used for provisioning has expired.

Solution

Work with the AWS administrator or AWS Support team to either generate a new SCIM API access token or rotate the expired access token on the AWS side, following AWS documentation: Automatic Provisioning - AWS IAM Identity Center.

 

  1. Access the Okta Admin Console.
  2. Navigate to the AWS app > Provisioning > Integration.
  3. Click Edit.
  4. Copy the newly-generated valid AWS SCIM API Access token and replace the old invalid AWS SCIM API token with the new valid AWS SCIM API token.
  5. Click the Test API Credentials button again and ensure it verifies successfully.
  6. Once verified, click Save
  7. Navigate to the Group Push tab, and click Push Now to re-attempt the group push. Confirm that the push group has been successfully pushed.


Related References

Loading
AWS IAM Identity Center - Group push mapping for the group could not take effect due to error: Error while creating user group: Unauthorized