<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

What is Okta Profile Sourcing and How is it Configured

Lifecycle Management
Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

A profile source is an application that acts as the source of truth for user identities in Okta. Administrators can prioritize multiple profile sources to manage the entire user lifecycle, including creation, updates, and deactivation. Configure an application as a profile source in the Okta Admin Console to synchronize user attributes from external directories or applications.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Profile Sourcing
  • Provisioning
  • Okta Integration Network (OIN)
  • Universal Directory
  • Lifecycle Management

Solution

What is an Okta profile source?

A profile source is an application that acts as the source of truth for user identities. When an administrator enables a profile source from the provisioning settings of the application or directory, it appears in the profile source list on the Profile Sources page. If an administrator does not identify an external profile source, Okta acts as the source for all profiles.

If more than one profile source exists, administrators can prioritize them so that different systems source user profile attributes based on their assignments. A user profile can only have one profile source at any given time.

Profile sources help manage the entire user lifecycle, including creation, updates, and deactivation. For example, Workday can act as a profile source to send user creation, updates, and termination events to Okta.

Review the following list of common applications and directories that support profile sourcing:

  • Active Directory
  • BambooHR
  • G Suite
  • LDAP
  • NetSuite
  • Namely
  • Salesforce
  • SuccessFactors
  • UltiPro
  • Workday

 

How is profile sourcing support determined for an application?

Determine whether an application supports profile sourcing by reviewing the use cases on the Applications Catalog page or checking the provisioning capabilities.

  1. Review the use case on the Applications Catalog page.
    Use Case on the Applications Catalog page
  2. Verify the application provisioning section lists attribute sourcing capabilities.
    Provisioning capabilities

 

What are the considerations for enabling Profile Source and Update User Attributes simultaneously?

Administrators can enable Profile Source and Update User Attributes for the same application, allowing Okta to push profile mappings to the highest priority profile source. This synchronizes attributes, such as an email address and phone number, from downstream applications back to the profile source. However, data loss may occur if an application designated as a profile source also receives profile updates from Okta.

Consider the following risks before enabling both settings for the same application:

  • Unwanted profile pushes: Okta updates can overwrite the values of unmapped attributes in an application, even if that application is the highest-priority profile source. For example, if the cn attribute lacks a mapping from Active Directory to Okta, and the administrator configures Active Directory for Profile Source and Update User Attributes, Okta applies the default mapping to cn.
  • Overwritten identity provider-sourced attributes: Okta to application updates can overwrite attributes sourced by another identity source. Okta does not provide a partial push option.
  • Race conditions: Okta can overwrite an updated attribute in an identity source before pushing other updates back to Okta. For example, if a directory imports a user first name and last name into Okta, but an application imports the user email address into Okta, a last name change in the directory before the email address update in the application could cause Okta to push the new name and the old email address.

NOTE: Using a profile source necessitates a clear distinction between newly imported users and updates to current Okta users. Okta uses matching rules to maintain a link between the profile source and Okta to prevent conflicts. Review User Creation & Matching in Provisioning and Deprovisioning.

 

How is an application configured as a profile source?

Configure an application as a profile source by navigating to the application provisioning settings in the Okta Admin Console and enabling the profile sourcing option.

 

 

  1. Navigate to Applications > Applications in the Okta Admin Console.
  2. (Optional) Enter the application name in the Search field.
  3. Select the application name in the list of applications.
  4. Select the Provisioning tab.
  5. Select To Okta in the Settings list.
  6. Scroll to Profile & Lifecycle Sourcing, select Edit, and select the Allow <application_name> to source Okta users checkbox.
  7. Select OK in the Enable Profile Sourcing dialog box if it appears.
  8. (Optional) Select the desired action for when a user is deactivated in the application:
    • Do Nothing: Prevents activity in the application from controlling the user lifecycle. This still allows profile source control of attributes and mappings.
    • Deactivate: Allows Okta to automatically deactivate the user when deactivated in the target application. This is the default setting.
    • Suspend: Allows Okta to automatically suspend the user when deactivated in the target application.
  9. (Optional) Select the desired action for when a user is reactivated in the application:
    • Reactivate suspended Okta users: Allows Okta to reactivate a suspended Okta user when reactivated in the application.
    • Reactivate deactivated Okta users: Allows Okta to reactivate a deactivated Okta user when reactivated in the application.
  10. Select Save.

 

Related References

Loading
What is Okta Profile Sourcing and How is it Configured | Okta Support