<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007ORo8rCADOkta Classic EngineDirectoriesAnswered2022-12-22T22:28:39.000Z2022-01-17T18:49:41.000Z2022-01-19T18:44:45.000Z

DavidR.32530 (Customer) asked a question.

What value uses Okta to fill externalId attribute, during AD account import?

We have integrated Active Directory to import user into Okta and now we are planning to integrate O365 but only for authentication, provisioning from Okta to O365 is not planned to be implemented.

 

As part of this plan we validated if all the O365 immutableId's were loaded into Okta.

So first, we confirmed we had the immutableId on AD Onpremises, which was true. ImmutableId's are found at ms-ds-consistencyGUID in AD.

Next we validated at Okta if this value was loaded during imports and we found something strange. About 99% of the users created at Okta, that were imported from AD, have the immutableId at its externalId attribute. However 1% left, has another value that does not correspond with this value to the ms-ds-consistencyGUID on AD on premise corresponding account.

 

We have reviewed the profile mapping but externalId is not explicitely set to anything, so we are wondering what's the behavior by default for this integration? When Okta will pick ms-ds-consistencyGUID from AD and in which cases it will not?

 

Thanks in advance for any help or documentation that could someone provide us.


This question is closed.
Loading
What value uses Okta to fill externalId attribute, during AD account import?