Exclude AD username updates during provisioning
To ensure that provisioning events don't update the User Personal Name (UPN) or samAccountName in Active Directory (AD), change the mapping for these attributes.
- In the Admin Console, go to .
- Click Directories in the Filters list.
- For AD, click Mappings and select Configure User mappings.
- Click Okta to your AD instance.
- In the dropdown menu next to samAccountName, select Apply mapping on user create only.
- In the userName attribute immediately below the samAccountName attribute, click Override with mapping.
- In the dropdown menu next to userName, select Apply mapping on user create only.
- Click Save Mappings and Apply updates now.