
MilesG.56351 (Customer) asked a question.
Okta - AD Provisioning Issue
We are trying to test the provisioning feature from Okta to Azure AD using profile sync. Whenever we try we get an error message stating that "The domain portion of the userPrincipalName property is invalid. You must use one of the verified domain names in your organization.". Has anyone experienced this issue?

Hi @MilesG.56351 (Customer) , Thank you for reaching out to the Okta Community!
The application username format being passed from Okta to the downstream application needs to be the same as the expected value in Azure AD.
While the Okta username does not have to be the same as the Azure AD username, the value being passed along as an identifier needs to be.
For example, your Okta Username is " john.smith@companyHQ.com ", but your Azure AD domain is just " @company.com " , then the expected value would be " john.smith@company.com ".
This can be configured in the application settings on the Okta side, by either switching the username format from the default (typically Okta Username) to one of the other base attributes (most commonly email). There is also an option to use a custom username format, if the situation demands it.
This is also discussed in the following support article. Even though it mentions O365, it applies to Azure AD as well.
https://support.okta.com/help/s/article/office-365-provisioning-error-the-domain-portion-of-the-userprincipalname-property-is-invalid-you-must-use-one-of-the-verified-domain-names-in-your-organization?language=en_US
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
What you missed: new product releases and other announcements