Okta Office 365 Error "Your account has not been configured for this application"
Last Updated:
Overview
When a federated user attempts a Single Sign-On (SSO) flow into Microsoft Office 365, an account configuration error occurs. This error occurs because the ImmutableID value remains missing or does not match the existing ImmutableID value in the Microsoft user profile properties. Verifying the current ImmutableID value and updating the mapping in the Profile Editor resolves this issue. When this error occurs, Okta displays the following message:
Office 365 Login Failure
Your account has not been configured for this application. Please contact your Okta administrator and ask them to import your account from Active Directory.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365
- Single Sign-On (SSO)
- Federation
Cause
The ImmutableID value is either missing or does not match the existing ImmutableID value in the Microsoft user profile properties. The ImmutableID value remains blank if an on-premises Active Directory (AD) integration does not source the user. If no on-premises AD integration exists to map the value, the ImmutableID mapping requires a different Okta attribute that remains unique and static, such as the Okta user ID.
Solution
How do administrators verify the ImmutableID value?
Navigate to the Microsoft Office 365 application assignments in the Okta Admin Console and edit the user assignment to verify the current ImmutableID value.
- In the Okta Admin Console, go to Applications and select Applications.
- Select the Microsoft Office 365 integration.
- Select the Assignments tab.
- Select the Edit app assignment icon next to the affected user to verify the Immutable ID value. The value remains blank if an on-premises Active Directory (AD) integration does not source the user.
Update the ImmutableID Mapping in the Profile Editor
Navigate to the Profile Editor, select the Microsoft Office 365 application profile, and populate the ImmutableID value using the appropriate Okta Expression Language expression.
- In the Okta Admin Console, go to Directory and select Profile Editor.
- Select the application profile for the Microsoft Office 365 instance.
- Select Mappings and choose the Okta User to Office 365 section.
- Populate the ImmutableID value from Okta to Microsoft Office 365 using one of the following expressions.
- For non-AD users, use the following expression to set the Okta user ID as the ImmutableID.
user.getInternalProperty("id") - For both AD and non-AD users, use the following expression to populate the ImmutableID.
hasDirectoryUser()?findDirectoryUser().externalId:user.getInternalProperty("id")
- For non-AD users, use the following expression to set the Okta user ID as the ImmutableID.
NOTE: The second expression generates an ImmutableID value for an Okta user with or without an Active Directory assignment. The expression checks if the user possesses an Active Directory assignment. If true, it sets the ImmutableID using the Active Directory profile External ID field value. If false, it sets the ImmutableID using the Okta user ID value.
