Unable to Edit Okta User Profile Attributes
Last Updated:
Overview
An issue occurs where Okta user profile attributes appear uneditable because the profile is imported from an external source or the user profile is deactivated. Resolve this issue by changing the attribute source priority to Okta, updating the attribute in the external source, reactivating the user, or enabling updates to deactivated users.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- User Lifecycle Management
- Universal Directory
- Profile Attributes
Cause
Okta user profile attributes are uneditable in two scenarios. First, if the user profile originates from an external profile source, such as Active Directory (AD), Lightweight Directory Access Protocol (LDAP), a Human Resources Information System (HRIS), or another Identity Provider (IdP), Okta sets the attributes to inherit from the profile source by default. Second, Okta prevents updates to deactivated user profiles by default.
Review the user profile displaying an uneditable attribute in the Okta Admin Console.
Solution
How are externally sourced attributes updated?
Update the attribute in the external profile source and import it into Okta, or disconnect the user account from the sourced application within Okta, edit the fields, and reconnect the user. Alternatively, change the profile source priority to inherit from Okta by navigating to the Profile Editor, selecting the user profile, and modifying the source priority for the specific attribute.
- In the Okta Admin Console, go to Directory > Profile Editor.
- Click the name of the profile to edit, typically named User (default).
- Locate the attribute that requires modification and click the blue information icon to the right of the Attribute Type column.
- Change the Source priority to Inherit from Okta.
Update attributes for deactivated user profiles.
If the Okta user profile is deactivated, reactivate the user before making changes. Refer to How to Avoid Sending a Welcome Email to New Users to prevent sending a welcome email when updating the profile.
Review the user profile displaying a deactivated status in the Okta Admin Console.
How is the feature to edit deactivated user profiles enabled?
Enable the feature to allow direct updates to deactivated users in the Okta organization by navigating to the Directory settings and allowing updates to deactivated users. Note that imports from an external source into Okta do not update inactive users, Okta does not push changes to downstream applications, and updates do not generate a System Log event.
- In the Okta Admin Console, go to Directory > People.
- Click More Actions > Edit Deactivated User Profile Updates.
- Click Allow updates to deactivated users.
- Select the deactivated user account to edit and apply the necessary changes.
NOTE: Disable this feature by following the previous steps and clicking Stop updates to deactivated users.
