how to bulk import users into okta from the hr system
Explains bulk-creating Okta users from HR system exports: CSV import for one-time loads and HR-driven provisioning for ongoing sync. Covers required attributes, activation choices, and fixing failed rows. Use when onboarding a batch of users or seeding Okta from an HRIS. Not for single-user creation or tuning ongoing attribute sync.
TL;DR
For a one-time batch, use Okta's CSV import: build a clean file with firstName, lastName, login, and email, upload it under Directory > People > Add Person, and activate. For ongoing hires, skip CSV entirely and set up HR-driven provisioning so Okta stays in sync automatically. Clean the source data first: Okta trusts the file, so bad rows become bad accounts.
Steps
- Decide one-time vs ongoing. CSV import for a single batch; an HR-as-master integration for continuous sync. Expected: you can name which one this is before opening the console.
- Build the CSV with the required columns: firstName, lastName, login (usually the email address), email. Logins must be unique or the row fails. Expected: the file opens cleanly with no blank login cells.
- Import: Directory > People > Add Person > Import from CSV. Map the columns and choose Activate now vs Do not activate based on whether start dates are in the future. Expected: Okta reports the created count and lists any failing rows.
- Fix failed rows from the per-row errors (usually duplicate login or malformed email) and re-import only those rows. Expected: the second pass creates the remainder.
- Verify: spot-check several users for correct group and app assignments from your group rules. Expected: group membership matches what the HR data implied.
Use this when
- Onboarding a batch of new hires at once
- Seeding Okta from an HRIS export for the first time
- Migrating users from another directory into Okta
Not for this skill when
- Creating a single user (use the normal add-person flow)
- Keeping attributes in sync long-term (use HR-driven provisioning, not repeated CSVs)
- Importing into Customer Identity Cloud (different product, different flow)
Compatibility
- Okta Identity Engine, workforce tenants
- CSV import and HR-driven provisioning (Workday and similar HRIS connectors)
Variants
The HR system supports a connector: use HR-driven provisioning
HR as the profile master keeps attributes syncing automatically and handles future hires with no more CSVs. More setup up front, no repeat work after.
Start dates are in the future
Import deactivated and let a lifecycle rule activate accounts on day one.
Why it happens
Bulk import is attribute-driven: Okta creates exactly what the file says. Most failures trace back to dirty source data (duplicate logins, blank emails, wrong formats), not to Okta itself.
Edge cases
- Rehires: check for existing deactivated accounts before creating duplicates.
- Contractors with non-company emails: make sure the login format policy allows them.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_IJlqA4-Rt0JyX9PSDt2Edw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.