<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
When and Where Automations Applies
Lifecycle Management
Administration
Overview

Okta offers automations that allows admins to proactively manage the lifecycle of end users who are part of an Okta group. These automatons can be used to respond to specific use cases that arise during the user lifecycle, such as user inactivity and user password expiration in Okta.

Applies To
  • Automations
  • Lifecycle Management (LCM)
  • User Inactivity
  • Password Expiration
Solution

There are multiple situations in which Automation can be useful:

  • Okta Automation can be used for active users who have not logged into Okta for a defined number of days. In this context, active users refer to those who have active Okta accounts. Such accounts become active when users are added by administrators on the Manage Users page or when end users self-register in a custom app or the Okta Homepage, and email verification is not required. Additionally, user accounts can be explicitly activated by administrators.
  • Okta automation can also be used for inactive users who have not engaged in any activity on their active account for a specified period of time. For example, automation can send an alert to inactive users when they are about to be locked out.
  • Automations configured for User Inactivity in Okta work based on the user successfully Signing in to Okta if the user does not explicitly Sign in to the Okta User dashboard (User needs to have a User login to Okta - Success event which can be found by using the query eventType eq "user.session.start"). If the user just signs in directly to other applications, such as Microsoft 365, for example, that user does not have activity in Okta, and Automation configured to Change user lifecycle state in Okta will trigger when the condition is met.
When disabling the Okta automation, all scheduled deactivations, emails, or actions will be halted until the automation is reactivated, and any counters for inactivity will be reset.

NOTE: Okta automation for password expiration is not fully supported when users log in using delegated authentication with Active Directory. This is not the case when delegated authentication is turned off and the password policy is controlled by Okta, as mentioned in the automation documentation, this feature is fully supported with Okta Password.

Related References

 

Recommended content

Documentation
Automations
Documentation
Automations
Documentation
Add an automation
Documentation
Add an automation
Loading
When and Where Automations Applies