<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Import Roadblock Prevents New Imports From Running

Okta Integration Network
Okta Classic Engine

Overview

An import roadblock occurs in Okta when a high number of application unassignments or user deactivations trigger the import safeguard settings. Resolve this by canceling or resuming the import in the Import Monitoring report and verifying email delivery notifications in the System Log. When the import safeguard threshold is met, Okta stops the import before making changes and generates an error message.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Import Roadblocks
  • Import Safeguards
  • Import Safeguards Notification

Cause

The import safeguard settings stop an import before Okta makes changes if a specific number of application unassignments or user deactivations occur as a result of the import. The threshold represents the percentage of total users. Locate this setting under the Provisioning tab in the To Okta section for any application that has provisioning enabled.

 

Review the import safeguard setting located under the Provisioning tab in the Okta Admin Console.

 

Import Safeguard

Review the error message generated by Okta when the import safeguard threshold is met.

 

Error

Solution

How is an import roadblock resolved?

 

Locate more details about the import under Reports > Import Monitoring. Cancel the import until identifying the cause of the change, or resume the import if the changes are expected.

Review the import monitoring details to cancel or resume the import.

 

Import monitoring

Open a case with Okta Support if additional information regarding the users or groups that caused the roadblock is needed.

 

NOTE: As long as the roadblock import is present on the Okta tenant, Okta blocks all imports from all applications. The only way to proceed is to either cancel the roadblock import and investigate on the application side why the application removes the users, or resume the import if expecting the unassignments. If the application that manages the import is set as a profile source with the ability to deactivate users in Okta, this import removes the application assignments and deactivates the Okta accounts.

 

How are import safeguard notifications verified?

Okta notifies administrators when a high number of application unassignments occurs. Verify the email delivery status in the System Log and unblock the email address if the administrator does not receive a notification by following these steps.

  1. Search for the email delivery notification for the high number of application unassignments by using the debugContext.debugData.category eq "email.bulkAppUnassignmentAppLevelRoadblock" filter in the System Log.

  2. Verify if there is an Email delivery FAILURE: bounce or Email delivery FAILURE: dropped event after running the filter on the System Log.

    Review the email delivery failure event in the System Log to confirm if the notification bounced or dropped.

    System log
  3. Follow the How to Unblock an Email Address from the Okta Email Address Bounce List via API guide to unblock the email address.

Related References

Loading
Okta Import Roadblock Prevents New Imports From Running | Okta Support