<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta User Profile Attribute Fails to Update During Just-In-Time Provisioning

Lifecycle Management
Okta Classic Engine
Okta Identity Engine

Overview

Okta fails to update user profile attributes during Just-In-Time (JIT) provisioning from an external Identity Provider (IdP) when attribute-level sourcing is incorrectly configured. Configuring the attribute source priority to override the profile source resolves this issue. The issue occurs even when the profile sourcing and profile mappings are configured correctly for the external IdP, although JIT provisioning functions as expected when creating a new user.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Just-In-Time (JIT) Provisioning
  • Inbound Security Assertion Markup Language (SAML)
  • Org2Org
  • Attribute Level Sourcing

Cause

The issue occurs because attribute-level sourcing is incorrectly configured for the external Identity Provider (IdP).

Solution

How is the user profile attribute updated during Just-In-Time provisioning?

Configure the attribute source priority to override the profile source and select the inbound Identity Provider in the Okta Admin Console.

  1. Navigate to the Okta Admin Console and go to Directory > Profile Editor.
  2. Select Okta User (default) to edit the Okta profile.
  3. Select the Information (i) icon for a predefined attribute or the Edit (pencil) icon for a custom attribute next to the attribute that requires updating via JIT provisioning from the inbound IdP.
  4. Select Override profile source from the Source priority dropdown menu.
  5. Select the name of the inbound IdP from the Add source dropdown menu.
    Inbound IdP

 

NOTE: Administrators can add multiple profile sources using the dropdown menu. Define priorities by dragging and dropping the sources as needed if there are multiple sources for the attribute.

 

Related References

Loading
Okta Support - Okta User Profile Attribute Fails to Update During Just-In-Time Provisioning