Best Practices When Switching From One Profile Source to Another in Okta
Last Updated:
Overview
Switching profile sources in Okta requires a gradual, supervised transition to prevent data loss and user lockouts. Administrators must test the transition on a single user, modify attribute-level sourcing, and disable profile sourcing in stages. Engage the Okta Professional Services team for specialized assistance with complex transitions.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Universal Directory
- Profile Sourcing
- Active Directory
- BambooHR
- Workday
- SuccessFactors
Solution
What are the best practices for switching profile sources in Okta?
Safely remove an application as the profile source in Okta by testing the transition on a single user, modifying attribute-level sourcing, and disabling profile sourcing in stages.
NOTE: Perform these steps in an Okta Preview or non-production environment first to verify the process and identify potential issues before making changes in the production environment.
- Identify a single, non-critical user account to test the impact of removing the profile source.
- Remove the application assignment from the test user by navigating to the user profile, selecting the Applications tab, and removing the assignment of the application currently acting as the profile source.
- Examine the Okta profile of the test user and note any changes to the attributes previously sourced by the application to identify affected attributes.
- Modify attribute-level sourcing by navigating to Directory > Profile Editor in the Okta Admin Console.
- Locate and select the Okta user profile.
- Review the attribute sourcing for each attribute currently sourced by the application that requires removal, select the information icon (blue button), select Source priority, and choose Inherit from Okta.
- Select Save Attribute.
- Verify that all necessary user attribute values are present and correct in the Okta user profile before disconnecting the application. Administrators must address any missing or incorrect attributes after disconnecting the application.
- Set the import schedule to Manual or Never Import in the application provisioning settings to disable scheduled imports and prevent automatic updates during the disconnection process.
- Disable profile sourcing by clearing the Allow Active Directory to source Okta users checkbox (or the equivalent setting for the specific application) in the Provisioning section under To Okta.
- Review the attribute mappings in the Profile Editor and adjust them to ensure Okta updates user profiles correctly after disconnecting the application. This process may involve mapping attributes to different sources or setting default values.
- Update any incorrect or missing attributes manually in the Okta Admin Console or via a bulk Comma-Separated Values (CSV) import.
