This document explains why it is not possible to map attributes in Okta to the 'name' attribute in Active Directory.
- Active Directory
- Profile Mappings
- Active Directory 'name' Attribute
The 'name' attribute cannot be mapped from Okta to Active Directory. The 'name' attribute is a Read-Only, System-Only Optional attribute. The 'name' attribute is tied to the "Full Name" attribute. The 'name' attribute will reflect the 'Full Name' attribute when an object is created.
The 'name' attribute is also tied to the common name. Two users with the same cn/name in the same OU cannot exist simultaneously because their distinguishedNames will be the exact same. However, two users with different cn/name properties with the same display name can exist.
To update a user's 'name' attribute please perform the change in Active Directory directly by editing the "Full Name" attribute.
