Okta AD Agent and LDAPS Support
Last Updated:
Overview
The Okta Active Directory (AD) Agent supports communication over Lightweight Directory Access Protocol (LDAP) over Secure Sockets Layer (SSL), known as LDAPS. Additionally, the AD Agent uses Kerberos encryption and authentication to secure data processed over the standard LDAP port (389).
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Kerberos Encryption
- LDAPS (LDAP over SSL)
Solution
How does the Okta Active Directory Agent secure communication with a domain?
Beginning with version 3.22.0, the Okta AD Agent supports communication over LDAPS (LDAP over SSL). Update to the latest version of the AD Agent to utilize this functionality.
The Okta AD Agent uses Kerberos encryption and Kerberos authentication to secure data traversing the standard LDAP port (389). Review the Microsoft documentation regarding Binding With Encryption for more information about Kerberos encryption.
