User Is Read-Only Due to Master App Instance IdP
Last Updated:
Overview
This article provides steps to resolve an issue where a user is unable to log in to the Okta org and receives the error message below, after entering their password and completing the MFA challenge. The issue is caused by a custom attribute that was added to the Okta User Profile and configured to be mastered by an IdP.
User x is read-only due to master app instance
Applies To
- Okta administrators who are experiencing the issue where a user is unable to log in due to the read-only status set by the IdP.
- Okta Identity Engine (OIE)
- Single Sign-On (SSO)
Cause
Solution
-
Uncheck the required attribute in the Okta User Profile.
-
Navigate to Security > Profile Enrollment > Default policy to access the relevant policy and delete the attribute requirement.
-
Delete the attribute from the Default Policy in Profile Enrollment and also the attribute in the Okta User Profile.
-
Test to ensure the user is now able to log in to the Okta org.
NOTE: If the attribute cannot be deleted from the Default Policy in Profile Enrollment, it may be used by other policies. In this case, review the policies and update them accordingly before proceeding with the deletion.
