Okta Group Push Relink Fails When Using Group Push by Rule
Last Updated:
Overview
Group push relinking fails when using a group push by rule configuration because Okta only supports group linking when pushing groups by name. This scenario occurs when Okta successfully pushes groups by name, Okta administrators unlink the groups but leave them in the target application, and then Okta administrators create a rule to relink them. The following Group Push error is displayed during the group push relink attempt:
"Group with same name already exists in AppInstance"
Applies To
-
Okta Identity Engine (OIE)
-
Okta Classic Engine
-
Group Push
-
Lifecycle Management
Cause
Okta does not support group push relinking when using a group push by rule configuration. Okta only supports group push linking when performing a group push by name. Once Okta administrators unlink a group but do not delete it in the external application, Okta cannot perform group push linking via a group push by rule configuration.
Solution
How is the group push relink error resolved?
Okta recommends creating a group push mapping by name to utilize the group push linking feature.
If a group push by rule is required, back up the external group data, delete the target group from the downstream application, and refresh the application groups in the Okta Admin Console.
-
Perform a full application group analysis in the downstream application to determine if it is safe to delete the pre-existing external application group. Ensure that user access does not depend on the pre-existing external group membership.
- NOTE: Obtain a list of pre-existing external group memberships and full access permissions granted to the target external group as a backup prior to any external group deletion. Direct any questions related to the external application group to the external application vendor support.
-
Delete the target application group from the downstream application. Verify the permanent deletion of the target group.
-
In the Okta Admin Console, navigate to Applications and select the target application.
-
Go to the Push Groups tab and select Refresh App Groups to ensure Okta deletes the previously imported application group from the Okta application import group list.
-
Retry the failed group push mapping by rule. Monitor the Okta group push mapping status to ensure it completes successfully without generating the previous error.
