Okta Office 365 Provisioning Fails With Application Registration Not Found Error
Last Updated:
Overview
An Office 365 provisioning failure occurs when a Microsoft tenant misconfiguration prevents Okta from completing the required update action. Resolve this by reviewing the Microsoft Audit log to identify and correct the misconfiguration before reauthenticating the integration. Reauthentication with Office 365 fails when the integration uses User Sync or Universal Sync, as described in Update Office 365 to Support Application-Based Authentication for Okta Provisioning. Okta displays the following validation error:
There was a failure while saving provisioning settings. Please grant consent by authenticating with Microsoft Graph on the Integrations page.
The Okta System Log records the following error:
Failed to finalize export to O365. received error: Application registration not found. Please re-authenticate to remediate the provisioning. SyncException Details: httpErrorCode=0, serverErrorCode=null
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365 Provisioning (User Sync or Universal Sync)
- Okta Integration Network (OIN)
Cause
A Microsoft tenant misconfiguration, often related to a custom Microsoft Conditional Access policy, prevents Okta from completing the required Update Microsoft Enterprise Application (Okta Microsoft Graph Client) action in the Microsoft tenant.
Solution
What steps resolve the Microsoft Office 365 provisioning error?
Authenticate with a Microsoft Global Administrator account, monitor the Microsoft Entra ID audit logs to identify the specific misconfiguration, and retry the reauthentication in the Okta Admin Console by following these steps:
- Enter a Microsoft Global Administrator credential with an active Multi-Factor Authentication (MFA) configuration when prompted to enter the Microsoft user login to update the provisioning settings in Okta.
- Monitor the Microsoft Tenant Audit log in real time for potential Update Application failure event logs to diagnose the root cause. For example,
- Review and investigate the Microsoft Audit failure log event to determine the root cause and address it accordingly from the external Microsoft platform configuration.
- Navigate to the Okta Admin Console and go to Applications > Applications.
- Select the Microsoft Office 365 application.
- Go to the Provisioning tab and select Integration in the left menu.
- Click Edit and retry the Reauthenticate with Microsoft Office 365 action.
- Verify that the reauthentication with Office 365 validates successfully in the Okta Admin Console and displays a successful Microsoft Audit log entry in MS Entra ID Admin Console. For example,
