How to Use the Okta Force Sync Option
Last Updated:
Overview
Okta can synchronize attributes across multiple user stores through mappings, which are maintained in Okta as AppUser profiles. The synchronization is typically automatic, but sometimes, it might fail for various reasons.
The Okta Force Sync feature allows administrators to manually initiate the synchronization of user data between the Okta user profile and the application user profile. Initiate a force synchronization by accessing the application provisioning settings and selecting the Force Sync option for the desired direction to reconcile the configured profile mappings.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Universal Directory
- Lifecycle Management
- Provisioning
Solution
Check out the video or the steps below.
How is a force synchronization initiated in Okta?
NOTE: The Force Sync option requires a provisioning-enabled application.
Initiate a force synchronization by accessing the application provisioning settings and selecting the Force Sync option for the desired direction.
- Access the Provisioning tab of the application.
- Select the To App or the To Okta section, depending on the required synchronization direction.
- Scroll down and select Force Sync above the list of mapped attributes for the application.
- Verify the brief message appears, signaling that the process started. Depending on the number of assigned users, this process requires additional time to complete.
NOTE: Force Sync from the To App section does not request that Okta push all assigned user profiles via the System for Cross-domain Identity Management (SCIM) or via the API to the external service. While this often results in application user profile provisioning push events, Okta only prompts a new push attempt to the external service when it detects a change in the application user profile from the last successful provisioning event.
NOTE: A force synchronization causes Okta to reapply the mapping on other profile sources, even if triggered from a secondary profile source.
Troubleshoot unsuccessful force synchronization requests.
If a force synchronization request does not result in the expected updates in the target downstream service after a reasonable amount of time, verify that the application user profile attributes were updated successfully in the application assignments.
- Navigate to the Assignments tab of the application to verify the application user profile attributes.
- If the attributes display correctly in the application user profile, refer to Okta is Not Updating Users' Attributes in Some Applications for further troubleshooting of the integration.
- If the application user profile attributes do not update as expected, review the existing application attribute mapping and preview the results for an example user to ensure Okta populates the expected results. Refine the mapping expression if necessary.
