External Authentication : FAQ

QuestionAnswerReferences
Why am I no longer able to change the rep:externalId?Since Oak 1.5.8 the default sync mechanism properly protects the system maintained property rep:externalId which is used to link a given synced user/group account to the corresponding entry on the external IDP.See documentation and OAK-4301
Why does a User or Group created with a content package not get synced with the IDP?Only users/groups with a rep:externalId linking them to the external IDP will be respected during the default sync mechanism.See also OAK-4397 and OAK-5304