<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Users Are Deactivated Instead of Suspended When Deactivated in Workday

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

When Workday deactivates a user, Okta deactivates the user instead of suspending them if the user account has a Staged status. To resolve this, ensure the user account reaches an Active or Pending User Action status before Workday deactivates the user. When administrators configure the When a user is deactivated in the app option to Suspend in the Workday provisioning settings, Okta should suspend the user. However, Okta deactivates the user instead.

Profile & Lifecycle Sourcing 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Workday
  • Profile & Lifecycle Sourcing
  • Provisioning

Cause

The user account in Okta has a Staged status. Accounts have a Staged status when Okta first creates them before the activation flow initiates or if a pending administrator action exists. Okta does not support suspending a staged account. Therefore, when Workday deactivates the user, Okta deactivates the staged account instead of suspending it.

Solution

Why does Okta deactivate staged users instead of suspending them?

Okta requires an account to have an Active or Pending User Action status to support suspension. When Workday deactivates a user, Okta evaluates the current account status. If the account is Staged, Okta bypasses the suspend configuration and deactivates the account.

 

What steps resolve the suspension behavior for Workday users?

Ensure that user accounts complete the activation flow before Workday deactivates the user by following these steps.

  1. Verify that the user account in Okta has an Active or Pending User Action status.
  2. Navigate to Okta Admin Console > Applications > Applications > Workday > Provisioning > To Okta > Profile & Lifecycle Sourcing and set the When a user is deactivated in the app option to Suspend.
  3. Deactivate the user in Workday.
  4. Verify that Okta successfully suspends the user account.

 

Related References

Loading
Okta Users Are Deactivated Instead of Suspended When Deactivated in Workday | Okta Support