<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
SAML Assertion Does Not Update the User Profile Attribute(s) when Authenticating via External IdP
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

Secure Assertion Markup Language (SAML) assertion from external IdP does not update attribute(s) even when the "Updates attributes for existing user" under JIT configuration and profile mapping is done correctly for the external IdP.

Applies To
  • External Secure Assertion Markup Language (SAML) IdP
Cause
Attribute-level sourcing has been incorrectly configured.
Solution

If the SAML assertion from the external IdP does not update the user profile attributes, please verify the below:

The Identity Provider

  1. In the Okta admin dashboard, go to Security > Identity Providers and select IdP.
  2. Click Actions and Configure Identity Provider.
  3. Under General Settings, click Edit.
  4. Under JIT Setting, make sure to have Update attributes for existing users selected.

JIT Settings

The IdP Mapping

  1. In the Okta admin dashboard, go to Security > Identity Providers and select IdP.
  2. Click Actions and Edit Profile and Mappings.
  3. Click on Mappings > Configure User mappings
  4. Check on Preview to make sure the mapping is correct.
    Preview section 

The profile source priority

In the Okta admin dashboard, under Directory > Profile EditorOkta User (default) > Profile source priorityUpdate profile sources configuration and put the IdP at the one with priority if it is not already.


If none of these fixes the situation, contact Okta support for assistance. 

Loading
SAML Assertion Does Not Update the User Profile Attribute(s) when Authenticating via External IdP