<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

GitHub Users Are Not Deprovisioned After Being Unassigned From the Okta Application

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

A user remains in the GitHub organization and teams after an administrator unassigns them from the GitHub application in Okta. This issue occurs when the affected user lacks the External ID attribute because the user assignment occurred before an administrator enabled provisioning. Reassigning the user to the GitHub application in Okta and then removing the assignment resolves the issue.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • GitHub
  • Deprovisioning

Cause

The affected user lacks the External ID attribute. Assigning the user before enabling provisioning in the GitHub application prevents Okta from generating the External ID. A successful application membership removal and deprovision event generates the following two entries in the System Log:

  • application.user_membership.remove 
  • application.provision.user.deactivate

When users lack the External ID, the application.provision.user.deactivate event does not appear in the System Log for the affected user.

Solution

How is the deprovisioning issue resolved?

Push the deactivation call to GitHub by reassigning the affected user to the GitHub application in Okta and then removing the assignment.

  1. Assign the affected user to the GitHub application in Okta.
  2. Remove the application assignment for the user.

NOTE: Manually deprovision the user in GitHub if the user no longer exists in the Okta organization and cannot receive a new assignment.

Loading
GitHub Users Are Not Deprovisioned After Being Unassigned From the Okta Application | Okta Support