<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Unable to Configure Active Directory Attributes to Create and Update
Okta Classic Engine
Directories
Okta Identity Engine
Overview

This article explains why the Active Directory attributes cannot be changed from Create to Create and Update on the To Okta provisioning settings of the Integration. (The same steps from this article apply to any Profile Source, not just Active Directory.)

See the screenshot below where the Create and update option is greyed out.
Mappings 

 

NOTE: Selecting the Create and update option on the To Okta provisioning settings of the Integration does not reapply the mappings; in order to reapply the mappings as well, this change needs to be done from the Profile Editor section located under Directory.

Applies To
  • Directories
  • Active Directory (AD)
  • Provisioning
Cause

This issue is encountered because AD is not configured as the profile master. 

Solution

Under Directory > Directory Integrations > Active Directory instance > Provisioning to OktaProfile & Lifecycle Sourcing, the option Allow Active Directory to source Okta users needs to be enabled.

Profile & Lifecycle Sourcing 

Profile sourcing is enabled by default when the Okta Active Directory (AD) agent is installed. Profile sourcing makes AD the identity authority for connected users. When profile sourcing is enabled, Okta Admins cannot edit user profiles in Okta, and all changes are synchronized to Okta during provisioning events. If AD is disabled as the profile source, changes made in AD are not pushed to Okta.



Related References

Loading
Unable to Configure Active Directory Attributes to Create and Update