Okta Partial Match Settings Fail to Auto-Confirm New Active Directory Users
Last Updated:
Overview
When an Active Directory (AD) integration uses partial match settings to auto-confirm and auto-activate new users, Okta may still require manual intervention in the Import tab. This occurs when the AD account matches an Okta account already associated with the domain. Resolve this issue by manually reviewing the import and deciding on the appropriate next steps.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Imports
- Partial Matches
Cause
Partial match settings auto-confirm new users only if the AD account matches an Okta account that is not already assigned to the Active Directory instance. If the imported AD account matches an Okta account already associated with that domain, Okta halts the auto-confirmation process to prevent duplicate assignments.
Solution
How is the partial match import resolved?
Okta prevents manual confirmation of the match because an Okta user cannot have multiple assignments to a single Active Directory instance. Resolve the conflict in the Okta Admin Console by reviewing the matched user and selecting an alternative action.
- Navigate to the Import tab.
- Locate the matched user.
- Select an alternative action, such as ignoring the import or creating a new Okta user.
