Okta Workday Integration Deactivates Users in UTC Despite Timezone Aware Terminations
Last Updated:
Overview
The Okta Workday integration deactivates users in the Coordinated Universal Time (UTC) timezone instead of the local timezone when administrators use constrained security groups. Administrators must use an unconstrained security group to grant access to location data domains to ensure accurate timezone mapping. When a Workday user has the required location permissions and a configured location timezone, Okta should use the location timezone for timezone-aware terminations. However, Okta disables users at UTC time, as if administrators had not enabled the timezone-aware termination feature.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Workday
Cause
Constrained security groups do not support the timezone-aware termination feature. Constrained groups filter out global reference data, specifically the location objects that the integration requires to map a user location to a timezone. When the Okta integration cannot fetch this list, Okta defaults to UTC.
Solution
What configuration resolves the timezone-aware termination issue?
Workday native security architecture requires an unconstrained security group. Constrained security groups automatically filter out global reference data, such as the source location list. The Okta Workday integration must access the complete list of locations to map user time zones accurately. Assign the Workday Integration System User (ISU) to an unconstrained group, and grant Get/View access to public location data and to manage location domains.
- Location Data: Public
- Manage: Location
