<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Provisioning Error Matching User Not Found Occurs for Downstream Applications

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

Okta generates an error when attempting to provision a user account to a downstream application and cannot locate an existing user account. This occurs when the Create Users provisioning option remains inactive or when an administrator deletes an account directly in the application. Resolve this issue by unassigning and reassigning the user to the application in the Okta Admin Console. The following error message appears in the System Log or dashboard:

 

Automatic provisioning of user <user> to app <app> failed: Matching user not found

 

Matching User Not Found

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Integration Network (OIN)
  • Provisioning

Cause

Okta searches for an existing user account on the application side to verify if the username already exists before sending a provisioning request. When the Create Users provisioning option remains inactive, Okta only attempts to verify if a user with the specified username exists in the application. If no user exists, Okta generates the error. This error also occurs when Okta previously provisioned an account downstream into the application, but an administrator deactivated or deleted the account directly on the application side instead of through Okta.

Solution

What steps resolve the provisioning error for individual users?

Unassign and reassign the user to the Okta application to recreate the user account or trigger a new search.

  1. In the Okta Admin Console, navigate to Applications > Applications.
  2. Select the application.
  3. On the Assignments tab, search for the user.
  4. Unassign the user, and then reassign the user to the application.

 

What steps resolve the provisioning error for group users?

Convert the user assignment from a group assignment to an individual assignment before removing and reassigning the user.

  1. On the Assignments tab, search for the user, and select the pencil icon next to the user.
  2. Under Assignment Source, select Administrator. NOTE: This ensures that the application assigns the user individually and permits removal from the application without affecting the group assignment.
  3. Unassign the user from the application.
  4. Reassign the user to the application as an individual.
  5. Use the Convert assignments function to ensure that the application assigns the user based on existing group assignments.

 

How does Okta process the reassigned user?

When the Create Users provisioning option remains active, Okta creates a new user account to sync. Otherwise, Okta searches for the user in the application using the provided username. Verify the username by navigating to Applications > Assignments, selecting the pencil icon next to the user, and reviewing the Username field.

 

Related References

Loading
Okta Provisioning Error Matching User Not Found Occurs for Downstream Applications | Okta Support