GitHub Users Are Not Deprovisioned After Being Unassigned From the Okta Application
Last Updated:
Overview
A user remains in the GitHub organization and teams after an administrator unassigns them from the GitHub application in Okta. This issue occurs when the affected user lacks the External ID attribute because the user assignment occurred before an administrator enabled provisioning. Reassigning the user to the GitHub application in Okta and then removing the assignment resolves the issue.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- GitHub
- Deprovisioning
Cause
The affected user lacks the External ID attribute. Assigning the user before enabling provisioning in the GitHub application prevents Okta from generating the External ID. A successful application membership removal and deprovision event generates the following two entries in the System Log:
application.user_membership.removeapplication.provision.user.deactivate
When users lack the External ID, the application.provision.user.deactivate event does not appear in the System Log for the affected user.
Solution
How is the deprovisioning issue resolved?
Push the deactivation call to GitHub by reassigning the affected user to the GitHub application in Okta and then removing the assignment.
- Assign the affected user to the GitHub application in Okta.
- Remove the application assignment for the user.
NOTE: Manually deprovision the user in GitHub if the user no longer exists in the Okta organization and cannot receive a new assignment.
