29% of the exam — the second-largest domain.
6 sub-topics · this deck covers sub-topic 4 of 6
↑ Module 1 OverviewReal orgs rarely have just one system of record. This sub-topic is about what actually happens — and what can go wrong — when more than one app claims to be a profile source for the same user.
A profile source is "an app that acts as the source of truth for user identities." Once enabled, it can manage the full lifecycle — creation, updates, and deactivation.
When multiple sources exist, Okta lets you set a priority order — but only one profile source can serve a user's profile at any given time. Priority decides which one wins.
If both Profile Source and Update User Attributes are enabled on the same app, three specific things can go wrong:
To prevent this from spiraling, Okta uses matching rules to maintain a link between the profile source and Okta — distinguishing a brand-new imported user from an update to an existing one.
Watch for scenario questions built around these traps:
→ "Two sources are both configured as the profile source for the same user." = not possible — only one source can serve a profile at a time; priority order decides.
→ "An attribute from one IdP got silently overwritten." = the attribute-conflict risk of enabling Profile Source + Update User Attributes together.
Sources: help.okta.com — usgp-about-profile-sourcing.htm
Next: Sub 5 →