Okta Snowflake Push Group Error: Invalid Group Membership Value Specified
Last Updated:
Overview
A Snowflake Push Group fails in Okta when a user in the pushed group lacks provisioning in Snowflake or has an incorrect application user externalId. Resolve this issue by verifying that the user has an active Snowflake account and a matching externalId before retrying the group push. The following error appears in the Okta dashboard:
Unable to update Group Push mapping target App group <group name>: Error while creating user group <group name>: Bad Request. Errors reported by remote server: Invalid group membership value specified <externalId>
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Snowflake
- Provisioning
- Group Push
- Okta Integration Network (OIN)
Cause
The group push fails with this error if the user mentioned in the error message lacks provisioning and does not exist in the Snowflake application, or if the application user externalId is incorrect.
Solution
How is the Snowflake group push error resolved?
Validate the user account status in Okta and Snowflake, ensure externalId match, and retry the group push by following these steps.
- Verify that the pushed user has an active status in Okta, an assignment to the Snowflake application, and an active account in Snowflake.
- Confirm that the application user
externalIdon the assignment window matches theexternalIdin the Snowflake application. - Validate that the user mentioned in the error message has an active account in Snowflake application.
- Navigate to Applications > Applications > Snowflake > Push Groups.
- Attempt the group push again.
