Okta account exists but not ingested into ISC (not in Accounts or Uncorrelated)

We are using the Okta SaaS connector in Identity Security Cloud. A user exists in Okta and was created on Apr 24 by Okta System. The account is active. However, the account does not appear in ISC: not in Okta source Accounts and not in Uncorrelated Accounts. Aggregation runs successfully and Native Change Detection is disabled. User lifecycle, roles, and IAM groups are correct and provisioning events are firing. Provisioning from ISC fails with “login already exists”, which indicates ISC is attempting to create the account instead of correlating it. It appears the account was never ingested into ISC. Is there any supported way to bring a pre-existing Okta account into ISC without running a full aggregation?

@as5344, what you describe is really interesting. I’d start troubleshooting on the Okta side (personal preference), and some questions I’d ask include:

  • If you’re using an Okta API token does it have proper authorization - i.e., the correct admin level permission?
  • If you’re using OAuth2, does the scope have sufficient capability?
  • Are there any exclusions in Okta that might prevent this account from being seen and retrieved by external actors, such as Identity Security Cloud?
  • If all the above check out, then I’d try to find out what’s different about this account. For instance:
    • Does it show up in the same place as the other accounts in Okta, for example, is it listed along with the others in the Okta Admin GUI?
    • Does it have any account attributes that are different from the other Okta accounts - which are aggregating properly?
    • Is it missing any key Okta account attributes?

Then back in Identity Security Cloud I’d check:

  • Is there anything in the Okta source schema mapping that doesn’t make sense?
  • Are there any ISC rules being applied that may inadvertently cause this particular account to be ignored?
  • Are there any settings in the Okta SaaS connector that might be contributing to this behavior?

Also, I’m not aware of any way to aggregate and account individually that hasn’t already been aggregated into ISC.

Please let us know what you find, and if anyone else here has more ideas - please contribute to the discussion!