<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Office 365 Provisioning Error "Unable to update the specified properties for objects that have originated within an external service"

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

This issue occurs when Okta attempts to provision or update a user in Microsoft Office 365, but an on-premises Active Directory (AD) synchronizes the user object via Azure AD Connect. To resolve this, update the user attributes directly in the on-premises AD environment. When provisioning or updating a user in Office 365, Okta generates the following error:

 

Unable to update the specified properties for objects that have originated within an external service.



Unable to update the specified properties for objects that have originated within an external service.  

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Microsoft Office 365
  • Provisioning
  • Active Directory (AD)

Cause

The error occurs because an on-premises AD environment synchronizes the user object to Microsoft Azure Active Directory (Azure AD) using Azure AD Connect. Azure AD designates the on-premises AD as the source of truth for these synchronized objects. Consequently, Azure AD rejects any attempts by Okta to update attributes directly in the cloud.

 

The MS Graph API error is caused by a Microsoft Product Limitation:

  • "If a cloud-only user was previously synced from on-premises Active Directory, these properties can't be managed via the Microsoft Graph API. Instead, they can be managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell." 

Solution

How is the Office 365 provisioning error resolved?

Since a Microsoft Graph API product limitation causes this provisioning failure, administrators must seek an alternative to performing updates to the extensionAttribute fields via the Microsoft product feature directly. Consult the Microsoft Support Team for all available options.

 

Administrators can also explore Okta Workflows to create a custom solution. Contact the Okta Professional Services team for custom workflow design and implementation assistance.

 

How are the attribute mappings updated?

Navigate to the Profile Editor in the Okta Admin Console, locate the Office 365 app instance, and change the mapping behavior for the affected attributes to prevent Okta from pushing them.

  1. Navigate to Directory, and then select Profile Editor.
  2. Search for the Office 365 app instance and select Mappings.
  3. Choose the Okta User to Office 365 tab.
  4. Locate the mappings for extensionAttributes1 through extensionAttributes15.
  5. Change the mapping behavior for these attributes to Apply mapping on user create only or Do Not Map.
  6. Save the mappings and retry the provisioning task.

 

NOTE: If extensionAttributes1 to extensionAttributes15 turn out to be in order, verify the showInAddressLists attribute and apply the same steps to this attribute as well.

Recommended content

Loading
Okta Support - Okta Office 365 Provisioning Error "Unable to update the specified properties for objects that have originated within an external service"