Okta Slack Provisioning Fails With Cannot Modify GDPR Error
Last Updated:
Overview
When provisioning users to Slack, Okta generates a General Data Protection Regulation (GDPR) error if Slack marks the user profile as uneditable due to a data deletion request. Administrators can resolve this by temporarily disabling the deactivation provisioning feature and reassigning the application to the affected users. This issue occurs when Okta utilizes application programming interfaces (APIs) via the System for Cross-domain Identity Management (SCIM) protocol, yielding the following error:
Errors":{"description":"cannot_modify_gdpr (user=<X>)","code":403}
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Slack
- System for Cross-domain Identity Management (SCIM)
- User Provisioning
Cause
When Okta pushes a profile update to Slack, the operation fails if the user previously requested personal information deletion under the General Data Protection Regulation (GDPR). Slack marks the profile as uneditable due to the GDPR data deletion, causing the provisioning update to fail.
Solution
What steps resolve the Slack GDPR provisioning error?
Disable the deactivation provisioning option, reassign the application to the affected users, and re-enable the deactivation feature to clear the error.
- Navigate to the Provisioning tab of the Slack application in the Okta Admin Console.
- Clear the Deactivate Users provisioning option.
- Unassign and reassign the application to the affected users.
- NOTE: If the users receive assignments via group membership, convert the assignment to an individual assignment, unassign the application, and reassign the application to the users. Afterward, convert the assignment back to the group.
- Select the Deactivate Users provisioning option to re-enable it.
