<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009AmiRKCAZOkta Identity EngineIdentity GovernanceAnswered2025-03-22T09:03:26.000Z2023-05-10T18:31:35.000Z2023-05-16T11:12:57.000Z

xtb9q (xtb9q) asked a question.

To create AD account in disabled status ahead of joining date

 

If there is requirement to create user profile in Okta from HR/Authoritative source 2 days in advance and create AD account in disabled status, how we can achieve this in Okta? does it require Okta workflow implementation or if this can be achieved through any other configuration?


  • NiallM.34104 (Atlas Identity)

    So then when you activate them ( manually or via a simple workflow ) the Okta account will activate, followed by the AD account being activated.

     

    Now you just have to handle the password 🙂

    Selected as Best
  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @xtb9q (xtb9q)​ 

     

    Thank you for posting on our Community page!

     

    You can create users in Staged status before activation:

    https://help.okta.com/en-us/Content/Topics/users-groups-profiles/usgp-end-user-states.htm

     

    You can also check out this article about validating in Staged status:

    https://support.okta.com/help/s/article/How-can-a-users-identity-be-validated-before-they-are-activated-in-Okta?language=en_US

     

    Thank you for reaching out to our Community and have a great day!

     

    _____________________________________________________________________________

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    _____________________________________________________________________________

    Expand Post
  • NiallM.34104 (Atlas Identity)

    There's a few things to unpick there.

     

    create user profile in Okta from HR/Authoritative source 2 days in advance.....

    This depends on your HR and the integration with Okta. Usually the supported HR platforms have a lead time configuration that allows you to define the days before Start Date that the user is imported into Okta. You then have options in the configuration to Auto Confirm and Auto Activate based on what you want when the new started is imported.

     

    .... and create AD account in disabled status

    First question here is does it HAVE to be disabled. Is it enough that the user cannot use the AD account, or do you have process that means it must be created, but disabled ?

     

    If you have the HR integration above set to Auto Confirm, that will create the account in Okta in an Staged state. If the user has a group assignment that has an AD entitlement ( OU assigned ) then I think Okta will provision the account but it will be disabled ( AD account has about 23000 different states ).

     

    Expand Post
  • NiallM.34104 (Atlas Identity)

    So then when you activate them ( manually or via a simple workflow ) the Okta account will activate, followed by the AD account being activated.

     

    Now you just have to handle the password 🙂

    Selected as Best
  • xtb9q (xtb9q)

    Thank you @NiallM.34104 (Atlas Identity)​ - This helps, we are able to achieve our requirement with this

This question is closed.
Loading
To create AD account in disabled status ahead of joining date