Okta Incremental Import Fails to Relink Manually Unassigned Workday Users
Last Updated:
Overview
When an administrator manually unassigns a user from the Workday application in Okta, subsequent incremental imports fail to relink the user. This occurs because incremental imports only fetch data for workers with recent attribute updates in Workday. To resolve this issue, run a full import to synchronize all users and correctly match their profiles.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Workday
- Incremental Import
Cause
Incremental imports only fetch data for workers identified as having updates since the last incremental import. These updates must modify specific attributes, such as base attributes and non-effective future-dated custom attributes. Changes to effective-dated custom attributes alone do not trigger an incremental import. If no changes occur to base or custom attributes on the Workday side, an incremental import does not bring user data into Okta or link users appropriately.
NOTE: For Workday-sourced users, the standard procedure requires deactivating the user within Workday first. Following this, a full import operation should be executed, resulting in the deactivation of these users within Okta as well. Manually unassigning Workday-sourced users in Okta is not recommended.
Solution
How are manually unassigned Workday users linked back to Okta?
Verify the integration configuration and run a full import to relink the user by following these steps:
- Verify that the mapping between Workday and Okta accurately aligns with the specific use case.
- Run a full import rather than an incremental import to link or relink users. A full import synchronizes all users and ensures their profiles are correctly matched.
- Set up scheduled full imports at regular intervals to catch any changes or updates in Workday. This proactive approach ensures that the user data remains synchronized without manual intervention.
