Okta Does Not Support Partial Profile Push During Subsequent Profile Updates to External Applications
Last Updated:
Overview
Okta pushes the full application user profile during an update, which overwrites unmapped attributes on the service provider side. Removing the attribute from the Profile Editor prevents this overwrite. The observable issue occurs when Okta overwrites the external application's profile attributes on the service provider side after the activation of provisioning with the Update user attributes feature on the Okta integration when the attribute configuration is "Not Mapped."
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- System for Cross-domain Identity Management (SCIM) Provisioning
- Attribute Mapping
- Profile Push
Cause
When activating provisioning for an application that supports user synchronization and enabling the Update user attributes feature, Okta overwrites all attributes present in the Okta application user profile. Okta performs this overwrite even if the attributes lack mapping in the Profile Editor. The following image displays the Update user attributes feature within the provisioning settings.
Solution
How does Okta handle partial profile pushes during subsequent updates?
Okta does not support partial profile pushes. Okta pushes the full application user profile during a profile update, including attributes set to Apply mapping on user create only and Do Not map. If an attribute exists on the application's profile, Okta pushes it and overwrites the data on the service provider side, even if the value is empty or lacks mapping on the profile.
What steps prevent the attribute overwrite?
To avoid overwriting an attribute, remove the attribute from the Profile Editor of the application in Okta.
NOTE: Okta prevents the removal of base attributes.
