Verify the UPN and preferred_username Mapping
In the Okta OIDC app, verify that the user principal name (UPN) maps to the preferred_username
attribute. The Okta OIDC IdP app must send the UPN for the preferred_username claim in the ID token.
For information about provisioning users and groups in Secure Access, see Provision Users and Groups from Okta.