Active Directory (AD) attributes fail to sync to Okta when the attribute source priority is set to Inherit from Okta or the profile source has been overridden. To resolve this issue, change the attribute source priority to inherit from the profile source.
Verify that AD attributes do not successfully sync to the mapped Okta profile attributes, and the following conditions apply:
- AD is the Profile Source for the affected users.
- The Profile Editor mapping preview from AD successfully displays the attribute.
- The Okta attribute does not update successfully after a Full Import.
- The Okta attribute does not update successfully after a Force Sync on the To Okta section of the Provisioning tab of the Directory.
- There are no constraint violations in the System Log.
- The Okta attribute source priority is not set to Inherit from the profile source.
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Active Directory-Sourced Users
- Attribute Level Sourcing
If the source priority for the affected Okta user attribute is set to Inherit from Okta or Override profile source, Active Directory cannot update the attribute. This is expected behavior, as attributes are updated only according to the configured source priority in the Okta User Profile Editor settings.
How is the attribute source priority updated to allow Active Directory synchronization?
To allow AD to update Okta user attributes, navigate to the Profile Editor, locate the affected attribute, change the source priority to inherit from the profile source, and perform a force sync.
- Navigate to Directory > Profile Editor.
- Select the Okta User (default) profile.
- Find the affected attribute and select the Information icon for Okta base attributes or the pencil icon for custom attributes.
- Locate the source priority at the bottom of the attribute settings.
- Change the source priority to Inherit from profile source to enable AD updates.
- Navigate to Directory Integrations > Active Directory > Provisioning > To Okta.
- Scroll down to Okta Attribute Mappings and select Force Sync to ensure user profiles update successfully.
