Okta Group Push to AWS IAM Identity Center Fails with a Duplicate Resource Error
Last Updated:
Overview
An Okta Group Push to AWS Identity and Access Management (IAM) Identity Center fails when a group with the exact same name already exists in AWS. Resolve this issue by verifying the group push mapping type, linking the group by name, or contacting AWS Support to resolve the conflict. The following error appears in the Okta Admin Console:
Unable to update Group Push mapping target App group <group>: Error while creating user group <group>: Conflict. Errors reported by remote server: Refused to create a new, duplicate resource
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- AWS Identity and Access Management (IAM) Identity Center
- Provisioning
- Group Push
Cause
This error occurs because a group with the exact same name already exists in AWS IAM Identity Center. This causes the System for Cross-domain Identity Management (SCIM) Application Programming Interface (API) to reject the creation request from Okta as a duplicate resource. The AWS Knowledge Center discusses the AWS SCIM API provisioning error in full detail.
Solution
How is the duplicate resource error resolved?
Verify the group push mapping type, recreate the mapping by name if necessary, and retry the group push by following these steps.
- Verify the failed group push mappings to identify whether the Okta group push mapping type is By name or By rule. Group push linking only supports the By name mapping type. Once a group unlinks, Okta cannot relink it through a rule-based group push.
- If the failed group push uses the By rule type, unlink the group push. Recreate the push as By name and link it to the pre-existing AWS IAM Identity Center group with the matching group name.
- If the failed group push uses the By name type but still fails with the duplicate resource error, contact AWS Support to open a separate support ticket. AWS Support can assist in troubleshooting the conflicting group resources in the downstream AWS IAM Identity Center Console and advise on the best remediation action.
- Once AWS Support resolves the conflict in AWS, navigate to Applications > Applications > AWS IAM Identity Center > Push Groups in the Okta Admin Console and manually retry the failed group push.
