When using the Universal Sync provisioning type, any attribute change in Active Directory should sync to the Office 365 profile in Entra ID (known as Azure AD). In some cases, a change in last name, email or UPN can result in Okta being unable to find the Office 365 account. It will try to create a new account but fail due to the immutable ID already existing in Office 365.
- Directories
- Microsoft Office 365 Provisioning
- Universal Sync
Modify the UPN of the account in the Entra Admin Center to match the new username of the account in Okta. This will allow Okta to find and match with the account, updating the rest of the profile.
