<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Functional Behavior of the "Map primary email to login attribute" Feature in the Okta Admin Console User Creation
Okta Classic Engine
Okta Identity Engine
Lifecycle Management
Overview

This article explains the expected behavior when creating a user in the Okta Admin Console with the Map primary email to login attribute feature enabled.

Applies To
  • Okta Classic Engine
  • Okta Identity Engine (OIE)
  • Okta Admin Console
  • Okta User Creation
Cause

The Map primary email to login attribute feature is primarily designed for the Okta Classic Self-Service Registration (SSR) use case, as mentioned in the About self-service registration documentation.

Solution

The Map primary email to login attribute feature is primarily designed for the  Classic Self-Service Registration (SSR) use case. Consequently, admin console user creation does not enforce email uniqueness as stated in the Configuring the Map Primary Email to Login Attribute Setting documentation. 

 The following behaviors are expected when creating an Okta user through the Okta Admin Console while the Map primary email to login attribute feature is enabled:

  • If an existing user profile is updated with a new email address, the username is updated to match the email upon saving.
  • In the user creation dialog, if the email and username are entered as different values, validation does not occur to ensure uniqueness. The Okta user is created with differing username and email values. This is expected behavior.
  • If a created Okta user has a matching username and email initially, another user creation attempt using the same email is not permitted. The user interface displays an error indicating the account already exists.
  • If an Okta user is created with a different email and username, the same email can be used multiple times for different user creations as long as the username remains distinct.
Loading
Functional Behavior of the "Map primary email to login attribute" Feature in the Okta Admin Console User Creation