<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Active Directory User is Able to Access Okta Mobile while in Password Reset Status

Okta Classic Engine
Okta Identity Engine
Devices and Mobility
Administration

Overview

When an Active Directory Delegated Authenticated user was intentionally placed in a "Password Reset" status in order to prevent user access to resources in Okta, the account in Okta is still active. During the time that the Okta account was in a Password Reset status, the System Log showed activity tied to the user's account: Session created using API token. This log entry is a result of the user accessing Okta Mobile.
 

However, if the Admin triggers a Password Reset for a non-Delegated Authenticated user account (password managed by Okta), the user loses access to all Okta resources, including Okta Mobile.

 

Applies To

  • Active Directory (AD)
  • Delegated Authentication
  • Okta Mobile

 

Cause

Okta does not currently invalidate the Okta Mobile PIN nor the biometrics when a password reset is performed for Active Directory DelAuth user accounts.

Solution

If an Admin is looking to completely block access to all Okta resources, including Okta Mobile, but not deactivate the account, the recommended best practice is to place the account in a "Suspended" status in Okta.

Loading
Active Directory User is Able to Access Okta Mobile while in Password Reset Status | Okta Support