<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Matching AD/LDAP User to Okta User Works for Import but Not JIT
Directories
Overview
Okta is able to match an existing Okta user to an Active Directory or LDAP user via Import, but Just-in-time (JIT) provisioning creates a new user.
Applies To
  • Directories

  • Active Directory

  • JIT Provisioning

Cause
JIT account creation only works when the user does not exist in Okta. JIT is not able to assign a directory to an existing user. JIT is only able to sync profiles for a user already assigned to the directory.
Solution

This is expected behavior. Import the user using a scheduled or manual import to match an Active Directory account to an existing Okta user.


Related References

Loading
Matching AD/LDAP User to Okta User Works for Import but Not JIT