<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000028gnTq0AIOkta Classic EngineLifecycle ManagementAnswered2026-09-16T00:10:49.000Z2026-09-15T20:53:05.000Z2026-09-16T00:10:49.000Z

AdhithyaR.30076 (Customer) asked a question.

Provisioning Multiple SCIM Identities for a Single Okta User

Hi,

Is it possible for a single Okta user to be provisioned through SCIM using multiple different application usernames?

The downstream system requires the same user to be represented by more than one username. Each username is already available as an attribute in the user's Okta profile.

Is there a supported Okta pattern for provisioning these as separate downstream identities while maintaining a single Okta user as the source?

Would this require multiple instances of the SCIM application with different application username mappings, or is there another recommended approach?

Thanks!


  • Paul S. (Okta, Inc.)

    Hello @AdhithyaR.30076 (Customer)​  Thank you for posting on our Community page!

     

    Okta's standard SCIM provisioning model creates a one-to-one relationship between an Okta user and a downstream application user identity. Okta requires multiple instances of the SCIM application with different username mappings to provision a single Okta user to multiple downstream identities. A downstream system requires the same user to be represented by more than one username, but the SCIM specification and Okta provisioning engine do not natively support provisioning a single Okta user as multiple distinct downstream identities within a single application instance.

     

    Cause:

    The SCIM specification and the Okta provisioning engine do not natively support provisioning a single Okta user as multiple distinct downstream identities within a single application instance. The core workflow relies on a unique identifier to match Okta users to downstream users, and Okta enforces a single application username per user per application to maintain referential integrity.

     

    Solution:

    How does Okta provision a single user to multiple downstream identities?

     

    Create multiple instances of the SCIM application, configure each with a different application username mapping, and assign the user to each instance.

    1. Create the first SCIM application instance in Okta by navigating to Applications > Applications > Create App Integration, selecting the SCIM application template, and naming the application.
    2. Configure the first instance's username mapping by navigating to the application's Provisioning > Integration settings and setting the Unique identifier field for users to the first username attribute.
    3. Assign the Okta user to the first application instance to provision the user to the downstream system under the first username.
    4. Create a second SCIM application instance by repeating step 1 with a different name.
    5. Configure the second instance's username mapping to the second username attribute.
    6. Assign the same Okta user to the second application instance to provision the user to the downstream system under the second username.
    7. Verify the provisioning in the downstream system to confirm that both usernames are present and recognized as separate identities linked to the same Okta user.

     

    What are the important considerations for this configuration?

     

    Review the following considerations regarding provisioning state, updates, and deprovisioning when using multiple application instances.

    • Each SCIM application instance maintains its own provisioning state and external ID mapping. Ensure the downstream system handles multiple identities for the same Okta user without creating conflicts or duplicate records.
    • When the Okta user receives an update, both application instances send update requests to the downstream system. Coordinate with the downstream system's support team to confirm updates reconcile across multiple identities.
    • If either username attribute changes in Okta, the corresponding application instance triggers an update to the downstream system.
    • Deprovisioning the user from one application instance only removes that specific downstream identity, while the other remains active.

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post

Loading
Provisioning Multiple SCIM Identities for a Single Okta User