Configure Attribute-Level Sourcing for an Okta User Profile
Last Updated:
Overview
Configuring attribute-level sourcing for an Okta user profile populates the Okta profile with an attribute from a specific application. Administrators can achieve this by making the application the profile source, defining the attribute profile source, and mapping the profile attributes as detailed in the documentation on attribute-level sourcing.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Lifecycle Management
- Universal Directory
- Attribute-Level Sourcing
Solution
How is an application made the profile source?
Make the application the profile source by navigating to the Provisioning tab and enabling the profile sourcing option.
- Review the Make an app the profile source documentation.
- Enter the application name in the Search field.
- Select the application name in the list of applications.
- Select the Provisioning tab.
- Select To Okta in the Settings list.
- Scroll to Profile & Lifecycle Sourcing, select Edit, and select the checkbox.
- Select OK in the Enable Profile Sourcing dialog box if it appears.
- Select what occurs to the user when they are deactivated in the app:
- Do Nothing: Prevents activity in the app from controlling the user life cycle. This still allows profile source control of attributes and mappings.
- Deactivate: Deactivates the user automatically when deactivated in the target app.
- Suspend: Suspends the user automatically when deactivated in the target app.
- Select what occurs to a user when they are reactivated in the app:
- Reactivate suspended Okta users: Reactivates a suspended Okta user when they reactivate in the app.
- Reactivate deactivated Okta users: Reactivates a deactivated Okta user when they reactivate in the app.
- Select Save.
How is the attribute profile source defined?
Define the attribute profile source by navigating to the Profile Editor and configuring the source priority for the specific attribute.
- Review the Define the attribute profile source documentation.
- Navigate to Directory > Profile Editor in the Admin Console.
- Select Okta, Apps, Directories, or Identity Providers in the Filters list to filter the app list.
- Select Profile for the app, directory, or identity provider.
- Select All, Base, or Custom in the Filters list to filter the attribute list.
- Select the Information button in the right pane corresponding to the attribute intended for editing.
- Select one of these options in the Source priority list:
- Inherit from profile source: Select this option to make the profile source the attribute source.
- Inherit from Okta: Select this option to make Okta the attribute source.
- Override profile source: Select this option and then select a profile source to override the default profile source and make another profile source the attribute source. This option does not disable the app as a profile source.
- Select Save Attribute.
How are profile attributes mapped?
Map profile attributes by configuring the user mappings in the Profile Editor and applying the updates.
- Review the Map profile attributes documentation.
- Navigate to Directory > Profile Editor in the Admin Console.
- Select Mappings for the app and select Configure User mappings if a list appears.
- Select the App to Okta User tab in the User Profile Mappings dialog box.
- Map attributes by scrolling through the attribute mappings and ensuring that the required attributes in the target are mapped. The Okta or app user profile indicates which are required.
- Use the dropdown menu to add attributes, or use expressions to add attributes with concatenated or transformed values.
- Preview the mapping for a user.
- Select Save Mappings and Apply updates now.
