<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta User Assignment to Active Directory Fails with Error "Blank is an invalid value for organizationalUnit field"
Okta Classic Engine
Directories
Okta Identity Engine
Overview

An error occurs during Okta user assignment to Active Directory (AD) because the destination Organizational Unit (OU) is not specified. Specifying the destination OU for new users created in AD resolves this issue. When Okta users are assigned to AD, Okta generates the following errors:

 

Blank is an invalid value for organizationalUnit field (code blank).

 

User was assigned this application before Provisioning was enabled and not provisioned in the downstream application. Click Provision User.

 

Error Messages

Applies To
  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • Provisioning
Cause

The assigned destination OU for the user is not specified.

Solution

How is the blank organizational unit error resolved?

 

Specify the destination OU for new users created in AD by editing the assignment group directory configuration in the Admin Console, selecting the correct OU, and retrying the failed task from the dashboard.

  1. From the Admin Console, navigate to Directory, and then select Groups.
  2. Select the desired group for the group assignment.
  3. Select the Directories tab, and then click the Pencil icon.
    Directories
  4. Select an OU for the new users to be created in AD, and then click Confirm changes.
    Select OU
  5. Navigate to Dashboard, and then select Tasks.
  6. Select the failed task, and then click Retry Selected.
    Retry task
Loading
Okta User Assignment to Active Directory Fails with Error "Blank is an invalid value for organizationalUnit field"