<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
User Statuses in the Okta Admin Console
Administration
Okta Classic Engine
Okta Identity Engine
All Engines
Overview

The various user statuses that can be viewed in the Okta Password Health Report are described in this article. These statuses can also be seen in the Okta Admin Console on the People page and on each user's Profile page.

Applies To
  • Reporting
  • User Management
  • Okta Classic Engine
  • Okta Identity Engine (OIE)
Solution

What do the different user statuses mean?

The Okta Password Health Report contains multiple user statuses. Review the following table or watch the video for an explanation of each status:

 

API Status

Admin Console Label

Cause
StagedStagedAccounts have a staged status when they're first created, before the activation flow is initiated, or if there's a pending admin action.
ProvisionedPending user actionAccounts have a provisioned status, but the user hasn't provided verification by clicking through the activation email or provided a password.
ActiveActiveAccounts have an active status when:
  • An admin adds a user (Add person) on the People page and sets the user's password without requiring email verification.
  • An admin adds a user (Add person) on the People page, sets the user's password, and requires the user to set their password when they first sign in.
  • A user self-registers into a custom app or the Okta Homepage, and email verification isn't required.
  • An admin explicitly activates user accounts.
RecoveryPassword resetAccounts have a recovery status when an admin requests a password reset.
Password ExpiredPassword expiredAccounts have a password-expired status when the password has expired, and the account requires an update to the password before a user is granted access to apps.
Locked outLocked outAccounts have a locked-out status when the user exceeds the number of login attempts defined in the login policy.
SuspendedSuspendedAccounts have a suspended status when an admin explicitly suspends them. The user can't access apps, the Admin Console, or the Okta End-User Dashboard. App assignments are unaffected, and the user profile can be updated.
DeprovisionedDeactivatedAccounts have a deprovisioned status when an admin explicitly deactivates or deprovisions them. All app assignments are removed, and the password is permanently deleted.
 

    Related References

    Loading
    User Statuses in the Okta Admin Console