Okta Profile Push to Microsoft Office 365 Fails With AttributeValueMustBeUnique Error
Last Updated:
Overview
Okta fails to push a profile to Microsoft Office 365 and generates an AttributeValueMustBeUnique error when Microsoft Office 365 has not fully processed an account deletion. Resolve this issue by removing or modifying the duplicate proxy address in Microsoft Office 365 and retrying the task. Okta displays the following error in the System Log:
Could not create user <example@email.address> in Office 365, received error: Could not push profile for Office 365 user <example@email.address>, received error: [syncOperation=Set, alias=null, sourceAnchor=ks8VpQa/z1234567PZ0TVw/g==, userPrincipalName=<example@email.address>, mail=<example@email.address>, displayName=<displayName> *** System-use System-use, commonName=<commonName>] errorCode=AttributeValueMustBeUnique, errorDescription=Unable to update this object because the following attributes associated with this object have values that may already be associated with another object in your local directory services: [ProxyAddresses SMTP:<example@email.address>;]. Correct or remove the duplicate values in your local directory. Please refer to http://support.microsoft.com/kb/2647098 for more information on identifying objects with duplicate attribute values., info=null SyncException Details: httpErrorCode=0, serviceErrorCode=null
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365
- Profile Sync
Cause
Microsoft Office 365 requires time to complete the deletion process after an account removal. If Okta syncs a profile before the deletion finishes, the ProxyAddresses attribute value duplicates an existing object in the local directory services, resulting in a provisioning error.
Solution
How is the AttributeValueMustBeUnique error resolved?
Locate the duplicate proxy address in Microsoft Office 365, modify or remove the conflicting user, and retry the provisioning task in the Okta Admin Console.
- Search Microsoft Office 365 for a user with the duplicated
ProxyAddressvalue mentioned in the error message. - Delete the conflicting user or change the proxy address to a different value.
- Navigate to the Okta Admin Console.
- Go to Dashboard, and then select Tasks.
- Locate the failed provisioning task and retry it.
