<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006xKiq4CACOkta Classic EngineOkta Integration NetworkAnswered2021-12-20T16:51:40.000Z2021-05-07T18:35:18.000Z2021-05-10T21:17:58.000Z

RobertC.24968 (CARE Inc.) asked a question.

Unable to assign Office 365 Administrator roles via group membership

We've created some Okta groups to assign Administrator roles in Office 365, for example "Role - Security Admin" applies the User Administrator, Helpdesk Administrator, and Security Administrator roles, while "Role - Power BI Admin" applies User Administrator, Groups Administrator, and Power BI Administrator roles.

 

Every user that is assigned to one of these groups has the application push task fail, with the error:

An error occurred while provisioning O365

Automatic profile push of user <Display Name> to app Microsoft Office 365 failed: Could not push profile for Office 365 user <UserPrincipalName>, received error: Resource '<Azure AD Role Template GUID>' does not exist or one of its queried reference-property objects are not present. Please fix this on the Tasks Page

 

I have confirmed that each of the failed Template IDs in the error messages matches the ID for that Administrator role in our Azure AD environment.


  • User15932079466932298204 (Vendor Management)

    TThank you for reaching Okta Support. My name is Jose Sandoval and I will help you with this.

     

    Following the issue, there are a few things that we can test on the task error.

    • Go to O365 > Provisioning > Integration > Test Credentials again.
    • Go back to applications > More button > Refresh.

    As soon as we have completed that please go back to the users and retry the task. If this keeps failing please consider:

    • Change the assignment in one user from individual to group (vice-versa).
    • Retry the task.
    • Conver the assignment back to the group.
    • Retry the task.

    As additional steps, if all the users in the group have the same role go back to O365 > Assignments > Groups:

    • Add a new O365 role and save the changes.
    • Edit the group and remove the role added.
    • Go back to the task page and retry all the failed tasks.

    In case these the issue keep happening after the steps shared feel free to reach out to the Okta support line to coordinate a troubleshooting session.

    Expand Post
    Selected as Best
  • User15932079466932298204 (Vendor Management)

    TThank you for reaching Okta Support. My name is Jose Sandoval and I will help you with this.

     

    Following the issue, there are a few things that we can test on the task error.

    • Go to O365 > Provisioning > Integration > Test Credentials again.
    • Go back to applications > More button > Refresh.

    As soon as we have completed that please go back to the users and retry the task. If this keeps failing please consider:

    • Change the assignment in one user from individual to group (vice-versa).
    • Retry the task.
    • Conver the assignment back to the group.
    • Retry the task.

    As additional steps, if all the users in the group have the same role go back to O365 > Assignments > Groups:

    • Add a new O365 role and save the changes.
    • Edit the group and remove the role added.
    • Go back to the task page and retry all the failed tasks.

    In case these the issue keep happening after the steps shared feel free to reach out to the Okta support line to coordinate a troubleshooting session.

    Expand Post
    Selected as Best
  • RobertC.24968 (CARE Inc.)

    Hi Jose,

     

    Thank you. Selecting Applications>More button>Refresh imported and updated the roles, allowing the users to be refreshed without error.

This question is closed.
Loading
Unable to assign Office 365 Administrator roles via group membership