Active Directory Deletions and Okta Deactivations Cause Import Issues for Rehired Users
Last Updated:
Overview
When user accounts are deleted from Active Directory (AD) and deactivated in Okta, import issues occur when the users are rehired. This issue can occur when full imports are performed and Just-In-Time (JIT) provisioning is enabled.
This happens because the attribute used to create and match Okta users contains a different value from the original creation of the Okta user. Resolve this issue by performing a bulk user deletion via Postman, using Okta Workflows, or configuring Okta Automations to delete users upon deactivation.
As an example, Okta generates the following error during import when the SAMAccountName differs:
Create Okta User failed with the following validation errors: SAMAccountName field failed validation with value 'test.user@okta.com': An object with this field already exists in the current organization.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD) to Okta Imports
- Provisioning
Cause
The attribute that administrators use to create and match Okta users contains a different value from the original creation of the Okta user, resulting in failed Okta user creation errors when importing users.
Solution
Check the attribute mapping configuration causing the validation error.
Review the validation error message and the mapping configuration for the cited attribute in the Okta Admin Console. For reference, the SAMAccountName attribute is cited in the example error message above.
How are deactivated users deleted to resolve the import issue?
Resolve the import issue by permanently deleting the deactivated users using Postman, Okta Workflows, or Okta Automations.
- Use Postman to perform a bulk user delete by following the instructions in How to Bulk Delete Okta Users Using an API Client.
- Add a 1000 ms delay to help prevent hitting API limits when running a large batch of users.
- Use Okta Workflows to delete users upon deactivation.
- Use Okta Automations to deactivate and delete users.
Engage Okta Professional Services for a custom solution if the provided options do not meet the organizational requirements.
How can Okta Automations be configured to delete users?
Configure one to two automations to deactivate the user, send an inactivity email, and delete the user after a desired grace period to prevent deleting active users based solely on inactivity.
NOTE: A user is deleted if a delete automation is set based only on user inactivity after a certain number of days, regardless of the deactivation status.
Review the following examples of deactivation and deletion automations configured in an Okta environment.
