<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Google Workspace Provisioning Fails With Resource Not Found Error

Okta Integration Network
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

Okta generates a provisioning error for Google Workspace when the API credentials are invalid, the authentication token expires, the service account lacks permissions, or the user account is under a recovery security hold. Re-authenticating the API integration in the Okta Admin Console or waiting for the security hold to expire resolves this issue. The following error appears on the Okta dashboard during the provisioning flow:


Automatic provisioning of user <username> to app Google Workspace failed: Failed to push profile update. Resource Not Found: <resource>

 

Error Message

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Integration Network (OIN)
  • Google Workspace Provisioning
  • Application Programming Interface (API)

Cause

The error occurs due to one of the following reasons:

  • The Google Workspace administrator credentials used for the API connection are invalid.
  • The authentication token is invalid.
  • The account used for the API connection lacks the correct permissions in Google Workspace.
  • The user's Google account was recently recovered and remains under a security hold waiting period.

Solution

How is the Google Workspace resource not found error resolved?

Re-authenticate the Google Workspace API integration in the Okta Admin Console and retry the failed provisioning tasks.

  1. Navigate to the Okta Admin Console and go to Applications > Applications.
  2. Select the Google Workspace application.
  3. Go to the Provisioning tab and select Integration in the left settings menu.
  4. Select Edit.
  5. Select Re-authenticate with Google Workspace.
    Integration
  6. Enter the Google Workspace administrator username and password.
  7. Review the list of permissions Google grants Okta in the Google Workspace tenant and select Allow.
  8. Verify a message appears confirming the successful authentication on the Provisioning page in Okta.
  9. Select Save.
  10. Navigate to Dashboard > Tasks.
    Tasks
  11. Select the failed task and select Retry Selected.

Waiting for the Security Hold Period Resolves the Error for Recently Recovered Google Accounts

If the Google account was recently recovered, wait 24 to 48 hours for the recovered account to become fully active. Google places a security hold on recovered accounts as a security measure for the recovery process. Once the security hold period completes, proceed to retry the failed task or reassign the user to the application.

 

Related References

Loading
Okta Support - Okta Google Workspace Provisioning Fails With Resource Not Found Error