<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Updating the Workday Universal ID on the Okta User Profile

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

The Workday Universal ID links separate contractor and full-time worker profiles to prevent Okta from creating duplicate users during employee conversions. Administrators configure the Universal ID in Workday to allow Okta to filter out pre-hires and manage the transition seamlessly.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Workday
  • Provisioning
  • Universal ID
  • Universal Directory
  • Okta Integration Network (OIN)
  • Lifecycle Management

Solution

What is the Workday Universal ID?

In Workday, contractor and full-time workers are two separate entities with two separate Workday IDs. The Universal ID configuration allows administrators to link these entities together by setting the same secondary ID for both profiles.

The purpose of the Universal ID in Okta.

If administrators configure the Workday Provisioning integration with a pre-hire interval but do not configure the Universal ID, Okta pulls in the contractor worker and the future full-time user (pre-hire) simultaneously. Consequently, Okta creates a duplicate entry in the Import tab. This duplication occurs because the two workers possess different Workday IDs, preventing Okta from detecting that they are the same user.

 

How does Okta process the Universal ID during employee conversions?

When administrators configure the Universal ID in Workday as part of the contractor to full-time conversion feature, Okta detects if any incoming pre-hires share the same Universal ID as active, existing workers. Okta filters out these pre-hires while the existing workers with the matching Universal ID remain active.

 

When administrators deactivate the contractor worker and run the import from Workday, Okta selects the full-time user. Upon conversion, Okta deactivates and then reactivates the user. This behavior is expected because Okta views the contractor worker as terminated and the full-time worker as a new hire. This process supports scenarios where a contractor terminates, but the full-time hire date occurs on a different day.

 

If users are inactive in Okta when administrators set up the Universal ID, administrators must reactivate the accounts for the change to take effect. After Okta updates the attribute, administrators can deactivate the user again. To perform this action on a large number of users in bulk, administrators can use the Okta API via Postman.

 

Related References

Loading
Okta Support - Updating the Workday Universal ID on the Okta User Profile