<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta Force Sync Required for Specific Active Directory Properties to Sync
Okta Classic Engine
Directories
Okta Identity Engine
Overview

Updates to static values mapped to the Active Directory (AD) profile fail to push downstream. This occurs because assigning a static string value to a user requires a subsequent update to the appuser profile to trigger synchronization to Active Directory. Resolve this issue by manually running a Force Sync in the Okta Admin Console to push the updated attributes to Active Directory.

Applies To
  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • Universal Directory
  • Force Sync
Cause

Assigning a static string value mapped to the Active Directory profile requires a subsequent update to the application user (AppUser) profile to trigger automatic synchronization to Active Directory.

Solution

How are static Active Directory attributes synchronized from Okta?

 

Navigate to the Active Directory provisioning settings in the Okta Admin Console, then run a Force Sync to push the updated attributes to the downstream application.

  1. In the Okta Admin Console, navigate to Directory, and then select Directory Integrations.
  2. Select the Active Directory instance.
  3. Select the Provisioning tab.
  4. Scroll to the To Okta or To App section, depending on the required synchronization direction, and locate the Force Sync button above the list of mapped attributes.
  5. Select Force Sync. A brief message appears confirming the start of the process.
  6. Allow the synchronization to complete. The duration depends on the number of assigned users.

force sync button

 

Related References

Loading
Okta Force Sync Required for Specific Active Directory Properties to Sync