Create Only vs. Create and Update for Okta Profile Mappings
Last Updated:
Overview
When configuring user attribute mappings in Okta, administrators must choose between Apply mapping on user create only and Apply mapping on user create and update. These settings control how Okta populates the application user profile attributes during initial assignment and subsequent updates. Understanding the difference between these settings ensures Okta pushes the correct attribute values to downstream applications.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- User Lifecycle Management
- Profile Sources
- Profile Editor
- Attribute Mapping
Solution
What is the difference between Create Only and Create and Update mappings?
The user attribute mapping configuration settings Apply mapping on user create only and Apply mapping on user create and update refer to the Okta application user profile behavior. Configure these settings in the application mappings by navigating to Directory > Profile Editor > <application_name> > Mappings.
Similarly, the application attribute mappings for provisioning also have options for Create and Create and Update. These configuration settings specifically control provisioning pushes to a target application integration. Manage provisioning controls via the settings on the Provisioning tab in the To App section.
NOTE: This article focuses only on user attribute mapping configuration settings.
Profile attribute mapping involves multiple facets, including the upstream application profile (such as Active Directory), the Okta user profile, the application user profile (inside Okta, but specific to an application), and the profile on a downstream application. A visual representation of this flow is:
Upstream App Profile -> Okta User profile -> AppUser profile -> Downstream app.
Review the About Profile Types documentation for more information about profile types.
How does the Create and Update mapping function?
The Apply mapping on user create and update setting triggers a profile mapping update for the associated application user profile in Okta when Okta detects a change in one or more attributes in the expressions entered in the mapping fields.
How does the Create Only mapping function?
The Apply mapping on user create only setting refers to the creation of the application user profile in Okta. This mapping applies when creating the Okta user and application user profile association, leaving the attribute frozen in the application user profile. Subsequent provisioning events always push the same value by design. Review the Okta Does Not Support Partial Profile Push During Subsequent Profile Update Push from Okta to External Application documentation for more information.
This setting strongly enforces the same attribute value, and the only way to change the mapped value is by destroying and recreating the assignment. This is useful for attributes where an accidental update could cause adverse behavior, such as an employee ID or the Microsoft Office 365 immutable ID.
For example, if an administrator configures an attribute mapping as Apply mapping on user create only, Okta statically populates the company attribute on the application user profile using the value from the Okta user.Company attribute when assigning the user to the application.
Upon creation, the user settings appear as follows:
- AD Attribute = "ABC"
- Okta profile (
user.Company) = "ABC" - AppUser profile = "ABC"
- Downstream ServiceNow app = "ABC"
If the Okta attribute user.Company changes to a different value, the application user company value remains the same because the mapping only applies during user creation. If the AD attribute changes to "XYZ" and accepts updates, the settings appear as follows:
- AD Attribute = "XYZ"
- Okta profile = "XYZ"
- App user profile = "ABC"
- ServiceNow (Downstream) app = "ABC"
If Okta detects a change in any application user attributes, it pushes the entire application user profile, including unmapped attributes and those configured to apply on creation only. If a user changes the company value directly in ServiceNow from "ABC" to "XYZ", Okta detects the change to the application user profile and reverts the value back to "ABC" because Okta statically sets the value during creation.
If this is not the desired behavior, map attributes using either Apply mapping on user create and update or Do not map.
How are the application user profile values verified in Okta?
Verify the application user profile values by navigating to the application assignments in the Okta Admin Console and editing the specific user assignment.
- Navigate to Applications > Applications in the Okta Admin Console.
- Select the target application.
- Select the Assignments tab.
- Locate the user or group and select the edit icon (pencil) adjacent to the name.
