<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Active Directory Deletions and Okta Deactivations Cause Import Issues for Rehired Users

Lifecycle Management
Okta Integration Network
Okta Classic Engine
Directories
Okta Identity Engine

Overview

When user accounts are deleted from Active Directory (AD) and deactivated in Okta, import issues occur when the users are rehired. This issue can occur when full imports are performed and Just-In-Time (JIT) provisioning is enabled.

 

This happens because the attribute used to create and match Okta users contains a different value from the original creation of the Okta user. Resolve this issue by performing a bulk user deletion via Postman, using Okta Workflows, or configuring Okta Automations to delete users upon deactivation.

 

As an example, Okta generates the following error during import when the SAMAccountName differs:

Create Okta User failed with the following validation errors: SAMAccountName field failed validation with value 'test.user@okta.com': An object with this field already exists in the current organization.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD) to Okta Imports
  • Provisioning

Cause

The attribute that administrators use to create and match Okta users contains a different value from the original creation of the Okta user, resulting in failed Okta user creation errors when importing users.

Solution

Check the attribute mapping configuration causing the validation error.

Review the validation error message and the mapping configuration for the cited attribute in the Okta Admin Console. For reference, the SAMAccountName attribute is cited in the example error message above.

To Okta

To Okta

 

How are deactivated users deleted to resolve the import issue?

Resolve the import issue by permanently deleting the deactivated users using Postman, Okta Workflows, or Okta Automations.

 

 

Engage Okta Professional Services for a custom solution if the provided options do not meet the organizational requirements.

 

How can Okta Automations be configured to delete users?

Configure one to two automations to deactivate the user, send an inactivity email, and delete the user after a desired grace period to prevent deleting active users based solely on inactivity.

NOTE: A user is deleted if a delete automation is set based only on user inactivity after a certain number of days, regardless of the deactivation status.

Review the following examples of deactivation and deletion automations configured in an Okta environment.

Deactivation Automation

Delete User Automation

Loading
Active Directory Deletions and Okta Deactivations Cause Import Issues for Rehired Users | Okta Support