
JackC.72213 (Customer) asked a question.
We need to provide a mechanism to allow students to take control of their accounts for the first time. Their accounts are mastered in local Active Directory but the initial recovery email would need to be their personal email address and this cannot be attached to the local user object. Is there some solution that would allow us to use their personal contact email for initial account recovery?

Hi @JackC.72213 (Customer) , Thank you for reaching out to the Okta Community!
There is no out of the box solution for this. The only thing I can think of is to perhaps leverage the secondary email attribute.
https://support.okta.com/help/s/article/How-do-I-allow-end-users-to-receive-password-reset-or-activation-notifications-in-a-secondary-email-address?language=en_US
If the value for secondary email cannot be added straight from AD, you might be able to just do attribute-level sourcing for the secondary email to create the user in AD, import it, then as an Admin set the secondary email in the Okta user profile.
https://help.okta.com/en-us/Content/Topics/users-groups-profiles/usgp-about-attribute-sourcing.htm
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
The October issue of the Okta Community is here and packed with tips on certification, how to earn badges, and new releases. Let us help you stay connected.