<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
KERBEROS_ALIAS Blocks Okta Identity Engine Upgrade
Administration
Okta Classic Engine
Okta Identity Engine
Overview

The following reconfiguration has been identified as part of the preparation needed to perform the upgrade to Okta Identity Engine (OIE). Note that additional Okta features may require reconfiguration or be disabled in order to complete the upgrade. This article explains the prerequisites for upgrading to Okta Identity Engine (OIE) when Agentless Desktop Single Sign-On (ADSSO) or Office 365 silent activation is in use. 

The following error may be seen when attempting to upgrade:

Org has OFFICE365_WINDOWS_TRANSPORT_SUPPORT but not KERBEROS_ALIAS

 

Applies To
  • Okta Identity Engine Upgrade
  • Agentless Desktop Single Sign-On
  • Office 365 Silent Activation
  • KERBEROS_ALIAS
Cause

If the KERBEROS_ALIAS feature flag is not enabled for these configurations, an upgrade blocker can occur. If KERBEROS_ALIAS is not enabled and ADSSO and silent activation are enabled using the classic registry key method, some configuration items must be completed prior to scheduling the upgrade.

Solution
  1. In the Admin Console, go to Security > Delegated Authentication to determine if Agentless Desktop SSO is configured.
  2. Based on the configuration, follow the appropriate steps below.

    • If Agentless Desktop SSO is NOT configured
      • Contact Okta Support to enable the KERBEROS_ALIAS feature flag. No further action is required before the upgrade.

Agentless Desktop SSO NOT configured

    • If Agentless Desktop SSO IS configured

Agentless Desktop SSO is configured

      1. Modify the existing Active Directory (AD) service account. See Configure a service account for AD SSO for instructions.

      2. Configure all web browsers on domain-joined devices to add the new Kerberos Validator URL.

      3. After completing the reconfigurations, contact Okta Support to enable the KERBEROS_ALIAS feature flag before proceeding with the upgrade.

Related References

Loading
KERBEROS_ALIAS Blocks Okta Identity Engine Upgrade