## TL;DR
For a one-time batch, use Okta's CSV import: build a clean file with firstName, lastName, login, and email, upload it under Directory > People > Add Person, and activate. For ongoing hires, skip CSV entirely and set up HR-driven provisioning so Okta stays in sync automatically. Clean the source data first: Okta trusts the file, so bad rows become bad accounts.

## Steps
1. Decide one-time vs ongoing. CSV import for a single batch; an HR-as-master integration for continuous sync. Expected: you can name which one this is before opening the console.
2. Build the CSV with the required columns: firstName, lastName, login (usually the email address), email. Logins must be unique or the row fails. Expected: the file opens cleanly with no blank login cells.
3. Import: Directory > People > Add Person > Import from CSV. Map the columns and choose Activate now vs Do not activate based on whether start dates are in the future. Expected: Okta reports the created count and lists any failing rows.
4. Fix failed rows from the per-row errors (usually duplicate login or malformed email) and re-import only those rows. Expected: the second pass creates the remainder.
5. Verify: spot-check several users for correct group and app assignments from your group rules. Expected: group membership matches what the HR data implied.

## Use this when
- Onboarding a batch of new hires at once
- Seeding Okta from an HRIS export for the first time
- Migrating users from another directory into Okta

## Not for this skill when
- Creating a single user (use the normal add-person flow)
- Keeping attributes in sync long-term (use HR-driven provisioning, not repeated CSVs)
- Importing into Customer Identity Cloud (different product, different flow)

## Compatibility
- Okta Identity Engine, workforce tenants
- CSV import and HR-driven provisioning (Workday and similar HRIS connectors)

## Variants
### The HR system supports a connector: use HR-driven provisioning
HR as the profile master keeps attributes syncing automatically and handles future hires with no more CSVs. More setup up front, no repeat work after.
### Start dates are in the future
Import deactivated and let a lifecycle rule activate accounts on day one.

## Why it happens
Bulk import is attribute-driven: Okta creates exactly what the file says. Most failures trace back to dirty source data (duplicate logins, blank emails, wrong formats), not to Okta itself.

## Edge cases
- Rehires: check for existing deactivated accounts before creating duplicates.
- Contractors with non-company emails: make sure the login format policy allows them.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_IJlqA4-Rt0JyX9PSDt2Edw
