<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008C3jjuSABOkta Classic EngineAdministrationAnswered2024-04-30T09:27:24.000Z2016-07-26T18:11:04.000Z2020-08-18T00:44:25.000Z
Why am I getting "This choice creates a conflict" error for AD users?
Hello,

 

We are seeing several "This choice creates a conflict" error for AD users which are not getting Exact or Partial Match found. The settings for this AD are set to auto-confirm new users when No Import Match is found.

 

We are now unable to proceed getting this user activated.

Please advise.

 

Thanks,

Katie

  • Hi Katie 

     

    The answer to this question may take some investigation. It may be best to create a support ticket and let the support team help you get to the bottom of this. It sounds like a user already exists and that user conflicts with the user being imported from AD. If the user already exisits in Okta then it will not auto confirm that user because the user is not new. But this is only speculation, a full look into your tenant and configuration would yield a more precise resolution.
    Expand Post
  • Hi Katie,

     

    Usually a conflict is shown when the username value already exists in Okta for another account.  This could even happen for a deactivated user that is already consuming that username value.

     

    If you continue to have trouble activating users showing conflicts, please open a ticket with Okta Support and they will help you resolve the conflicts.

     

    Thanks,

    Patrick Wilcox

    Okta Technical Consultant
    Expand Post
  • 65rbr (65rbr)

    I opened a support case and it was determined that email address was missing in Active Directory.

    It would have been very helpful to have a more description message stating this instead of the cryptic "this choice creates a conflict" especially since there really was no conflict. We have found a feature request regarding more descriptive error messaging here.

     

    Thanks,

    Katie
    Expand Post
  • Hi,

     

    We were importing from an ou with a lot of unecessary users. the first time I imported, I ignored 33 of them. Then we moved the necessary users to their own ou and synced with that. After that I had the correct users in Okta, but the 33 "ignored" users were still ignored. I couldn't "create" them as new users because I got "this choice creates a conflict". (Apparently they did not satisfy the AD Agent settings based on their ou properties, but I didn't care about that since that ou was not used anymore and I just wanted to delete them).

     

    To solve that, I created a temporary placeholder user for each of those users in Okta (using a temporary email address that I recognized, something like "deleteme-username@yahoo.com"). Then I matched each of my "ignored" users to one of those temporary users which was allowed in Okta, and got rid of all the "ignored" users. After that I just deactivated/deleted each of the temporary placeholder users and they were gone.

     

    Now I am syncing from the appropriate ou which only contains the users that I need.

     

    good luck!
    Expand Post
  • 6c4y4 (6c4y4)

    For people that continue experiencing this today, my team found out that if the primary email is the same for various users, their username is overriden by that primary email and that causes conflict, since they all are technically the same user.

     

    Use the secondary email instead, and leave the primary email the same as the username. That solved the problem for us.

    Expand Post
This question is closed.
Loading
Why am I getting "This choice creates a conflict" error for AD users?