<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00002CW5L90ALOkta Classic EngineAuthenticationAnswered2026-10-05T15:39:06.000Z2026-09-30T07:22:50.000Z2026-10-05T15:39:06.000Z

kanakos.23654 (Customer) asked a question.

Questions Regarding User Profile Policy Configuration for Email Address Login

Hi Okta Community,

 

We currently use the Last Name.First Name format as the Okta login identifier. To allow users to log in using their email addresses as well, we are adding a custom attribute and configuring a User Profile Policy.

 

Currently, many user attributes are configured with the following source priority:

 

- Source priority: Inherit from profile source  

 1. CSV Directory  

 2. Active Directory  

 

We have two questions regarding this configuration.

 

①Impact of Changing the Source Priority for the Custom Attribute

 

If we configure only the newly added custom attribute with the following source priority, would this affect any other attributes or existing user data?

 

- Source priority: Override profile source  

 1. Active Directory  

 2. CSV Directory  

 

②Import Requirements After Adding a Custom Attribute

 

After adding the custom attribute, is it necessary to perform either a full import or an incremental import from Active Directory or CSV Directory in order for the attribute value to appear in the user profile?

 

Thank you very much for your support. 

We look forward to your guidance.

 


  • Paul S. (Okta, Inc.)

    Thank you for posting on our Community page!

     

    You are asking whether configuring a newly added custom attribute with a different source priority (Override profile source with Active Directory first, then CSV Directory) would affect existing attributes, and whether an import is required after adding the custom attribute for it to appear in user profiles.

     

    Short answer: Configuring source priority at the attribute level affects only that specific attribute and does not impact existing attributes or their data. However, an import may be necessary depending on how you populate the custom attribute values.

     

    Root Cause:

    Okta supports attribute-level sourcing, which allows individual attributes to have their own source priority independent of the profile master priority. When you configure source priority for a specific attribute using the "Override profile source" setting, that configuration applies only to that attribute. Other attributes continue to follow their existing source priority settings (in your case, "Inherit from profile source" with CSV Directory first, then Active Directory).

     

    Solution:

    Question ①: Impact of Changing Source Priority for the Custom Attribute

    Configuring the custom attribute with "Override profile source" and a different priority order will not affect any other attributes or existing user data. Here's why:

    1. Attribute-level sourcing is isolated. When you set a custom attribute to "Override profile source," you are creating a separate sourcing rule for that attribute only. The profile master priority (CSV Directory, then Active Directory) continues to govern all other attributes.
    2. Existing attributes remain unchanged. Attributes already configured with "Inherit from profile source" will continue to use the default profile master priority. Changing the source priority for one new custom attribute does not alter the source priority of existing attributes.
    3. No data loss or corruption. Setting a different source priority for the custom attribute does not modify, overwrite, or delete values in existing user attributes.

     

    Question ②: Import Requirements After Adding a Custom Attribute

    Whether you need to perform an import depends on how the custom attribute values will be populated:

    1. If the custom attribute is sourced from Active Directory or CSV Directory: You will need to perform an import (either full or incremental) from the respective directory after adding the attribute to the User Profile. The import ensures that Okta reads the attribute values from the directory source and populates them in user profiles. Without an import, the attribute will exist in the profile schema but will be empty for existing users.
    2. If the custom attribute is managed in Okta only: No import is required. You can manually populate the attribute values through the Okta Admin Console, the Okta API, or through application profile mappings.
    3. For new users created after the attribute is added: If the attribute is sourced from a directory, new users created via directory import will automatically have the attribute populated during the import process.

     

    Best Practice:

    After adding the custom attribute to your User Profile and configuring its source priority, perform an incremental import from Active Directory (your highest priority source for this attribute) to populate the custom attribute values for existing users. This ensures all users have the attribute value available for use as a login identifier.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Thank you for posting on our Community page!

     

    You are asking whether configuring a newly added custom attribute with a different source priority (Override profile source with Active Directory first, then CSV Directory) would affect existing attributes, and whether an import is required after adding the custom attribute for it to appear in user profiles.

     

    Short answer: Configuring source priority at the attribute level affects only that specific attribute and does not impact existing attributes or their data. However, an import may be necessary depending on how you populate the custom attribute values.

     

    Root Cause:

    Okta supports attribute-level sourcing, which allows individual attributes to have their own source priority independent of the profile master priority. When you configure source priority for a specific attribute using the "Override profile source" setting, that configuration applies only to that attribute. Other attributes continue to follow their existing source priority settings (in your case, "Inherit from profile source" with CSV Directory first, then Active Directory).

     

    Solution:

    Question ①: Impact of Changing Source Priority for the Custom Attribute

    Configuring the custom attribute with "Override profile source" and a different priority order will not affect any other attributes or existing user data. Here's why:

    1. Attribute-level sourcing is isolated. When you set a custom attribute to "Override profile source," you are creating a separate sourcing rule for that attribute only. The profile master priority (CSV Directory, then Active Directory) continues to govern all other attributes.
    2. Existing attributes remain unchanged. Attributes already configured with "Inherit from profile source" will continue to use the default profile master priority. Changing the source priority for one new custom attribute does not alter the source priority of existing attributes.
    3. No data loss or corruption. Setting a different source priority for the custom attribute does not modify, overwrite, or delete values in existing user attributes.

     

    Question ②: Import Requirements After Adding a Custom Attribute

    Whether you need to perform an import depends on how the custom attribute values will be populated:

    1. If the custom attribute is sourced from Active Directory or CSV Directory: You will need to perform an import (either full or incremental) from the respective directory after adding the attribute to the User Profile. The import ensures that Okta reads the attribute values from the directory source and populates them in user profiles. Without an import, the attribute will exist in the profile schema but will be empty for existing users.
    2. If the custom attribute is managed in Okta only: No import is required. You can manually populate the attribute values through the Okta Admin Console, the Okta API, or through application profile mappings.
    3. For new users created after the attribute is added: If the attribute is sourced from a directory, new users created via directory import will automatically have the attribute populated during the import process.

     

    Best Practice:

    After adding the custom attribute to your User Profile and configuring its source priority, perform an incremental import from Active Directory (your highest priority source for this attribute) to populate the custom attribute values for existing users. This ensures all users have the attribute value available for use as a login identifier.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • kanakos.23654 (Customer)

    Hi,

    I'm so sorry for the delayed response.

    Your explanation has clarified our questions and addressed our concerns.

    Thank you very much for your detailed and helpful response!

    ​

Loading
Questions Regarding User Profile Policy Configuration for Email Address Login