Convert an Okta User to the Federated Provider Type
Last Updated:
Overview
Administrators can convert an Okta user to the federated provider type by calling the Reset Password API. This process updates the user credential provider to federation, allowing the user to authenticate through an external identity provider.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta REST API
- Postman
Solution
What are the steps to convert an Okta user to the federated provider type?
Convert an Okta user to the federated provider type by executing a Reset Password API call with the provider parameter set to federation and verifying the updated status.
- Execute the Reset Password API call, passing
FEDERATIONas the provider parameter.
POST /api/v1/users/<USER_ID>/lifecycle/reset_password?provider=FEDERATION&sendEmail=false
2. Verify the user displays as FEDERATED by executing the GET user information API call.
NOTE: This API call may fail if the conversion occurs for an existing account that was previously converted (for example, from ACTIVE_DIRECTORY to OKTA), resulting in an HTTP 400 error and the following message:
Cannot convert user from OKTA to FEDERATION credential provider
In such a circumstance, open a case with Okta Support referencing this article.
NOTE: Convert a federated user back to an Okta user by executing the default API call.
POST /api/v1/users/<USER_ID>/lifecycle/reset_password?sendEmail=true
