Okta IWA Agent Installation Fails with Error Code 1000
Last Updated:
Overview
During the installation of the Desktop Single Sign-On (DSSO) Integrated Windows Authentication (IWA) Agent, the installer locates the service account but fails with the following error:
Unable to verify the service account. Error code: 1000.
The installation logs show the account validation fails with AD Error code 1329. Granting the service account the correct logon rights to the host workstation resolves the issue.
Applies To
- Active Directory (AD)
- Desktop Single Sign-on (DSSO)
- Integrated Windows Authentication (IWA) Agent
- Okta Classic Engine
Cause
Active Directory (AD) error code 1329 — ERROR_INVALID_WORKSTATION — indicates that the service account is not permitted to sign in to the workstation designated to host the IWA Agent. Because the installer cannot verify the account against that machine, Okta returns Error Code 1000 and the installation fails.
Solution
Granting Logon Rights to the IWA Agent Host Workstation
Grant the service account logon rights to the workstation that will host the IWA Agent and retry the installation.
