Okta Provisioning Error Occurs Due to Duplicate ProxyAddresses Property in Microsoft Office 365
Last Updated:
Overview
A duplicate proxy address in Active Directory (AD) or a shadow attribute conflict in Azure causes a Microsoft Office 365 provisioning error. Resolving the issue requires identifying the conflicting account and temporarily updating the proxy address to clear the shadow attribute.
When attempting to provision a user to Microsoft Office 365, an error occurs indicating that another object with the same value for the proxyAddresses property already exists.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365 provisioning
- Proxy addresses
Cause
A duplicate proxy address exists in AD, or a shadow attribute conflict exists in Azure preventing the profile push from Okta.
Solution
How is a duplicate proxy address verified in AD?
Verify if a duplicate proxy address exists in AD. Review the Microsoft video for instructions on locating and resolving duplicate proxy addresses in AD.
Clear the shadow attribute values in Azure to resolve the conflict.
If a duplicate proxy address does not exist in AD or Okta, a shadow attribute conflict in Azure prevents the profile push. Identify the conflicting account in the Azure logs, temporarily update the conflicting proxy address to clear the shadow attribute values, retry the Okta profile push, and revert the proxy address to the original value.
- Check the Azure or Microsoft Office 365 logs to determine which account conflicts with the proxy address of the user experiencing the error.
- Update the Username, User Principal Name (UPN), or Proxy address of the conflicting account in Microsoft Office 365 to a temporary value. Only update the values that conflict with the proxy address of the user experiencing the error.
NOTE: This temporary change clears the shadow attribute values of the user experiencing the error in Azure. A successful synchronization from Okta clears the incorrect proxy address value in the shadow attribute. - Navigate to the Tasks page in the Okta Admin Console and retry the profile push for the user experiencing the error.
- Revert the Username, UPN, or Proxy address of the conflicting account in Microsoft Office 365 to the original value.
The video below showcases an example:
