Okta User Profile Updates Not Pushed to Application After Provisioning Is Enabled
Last Updated:
Overview
Okta user profile updates fail to push to an application because the user profiles lack external IDs, or the required provisioning options remain disabled. Administrators resolve this issue by unassigning and reassigning the user to generate the external ID, or by enabling the correct provisioning options. When this issue occurs, Okta user profile updates, deactivations, and password syncs do not push from Okta to an application after enabling provisioning. Additionally, the Okta System Log mistakenly indicates that the push attempt succeeds.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Provisioning
- Profile Updates
Cause
Okta user profiles lack external IDs from an application, or required provisioning options remain disabled.
- Provisioning tasks require external IDs to ensure that Okta modifies the application user object.
- Okta creates external IDs only during the application assignment phase with provisioning enabled. If an administrator enables provisioning on an application already assigned to users, Okta does not create external IDs for those existing user assignments.
Solution
What steps resolve missing external IDs and provisioning options?
Check the user assignment for an external ID and unassign and reassign the user if the ID is missing.
- In the Okta Admin Console, navigate to Applications and select the affected application.
- Select the Assignments tab.
- In the left pane, select People and select the pencil icon adjacent to a user experiencing this behavior.
- Check to see if the External ID attribute is listed and populated.
-
- If there is no External ID:
- Unassign and reassign a user from the application. This will trigger a provisioning event from Okta to the application, creating an External ID that maps the Okta user object to the corresponding application's user object.
- If the External ID is present:
- Verify that the application's Provisioning options, such as Create Users or Deactivate Users, are enabled or disabled according to expected behavior.
- Check Dashboard > Tasks for profile update events. These will usually provide details about the cause of the issue.
- If there is no External ID:
