Okta External Identity Provider Authentication Fails With Multiple Matches Found Error
Last Updated:
Overview
An authentication error occurs during Just-In-Time (JIT) provisioning with an external Identity Provider (IdP) because multiple users share the same matching attribute value. Ensure the attribute value is unique for all users or select a different unique attribute to resolve the issue. Okta generates the following error in the System Log during external IdP authentication:
Authenticate user via IDP
FAILURE: Unable to match to a single transformed username, multiple matches found.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- External Identity Provider (IdP)
- Just-In-Time (JIT) Provisioning
Cause
Multiple users share the same value in the attribute designated for matching. For example, if the matching attribute is the employee number, two or more users possess the identical value for this attribute.
Review the external Identity Provider's authentication settings to determine where the matching attribute is defined.
Solution
How is the multiple matches found error resolved?
Ensure that the attribute value is unique for all users. If the value cannot change, select another attribute that contains a unique value for all users.
