<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Read-Only Domain Controllers Cause Okta Active Directory Provisioning Errors

Directories
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

Okta Active Directory provisioning and password changes fail when the Okta Active Directory (AD) Agent connects to a Read-Only Domain Controller (RODC). Ensure that RODCs do not accept LDAP requests in the environment to prevent these failures. The Okta AD Agent attempts to perform provisioning or password change tasks by making an LDAP call to the directory and interacting with the first domain controller that responds. The task fails if the responding controller is read-only.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Directories
  • Active Directory (AD)
  • Read-Only Domain Controller (RODC)
  • Provisioning
  • Password Changes

Cause

RODCs cannot modify any AD object. When the Okta AD Agent performs a provisioning or password change task, the Okta AD Agent initiates an LDAP call to the directory and interacts with the first domain controller that responds. The attempt fails if the responding server is an RODC.

Solution

What steps prevent Read-Only Domain Controllers from causing Okta provisioning errors?

Configure the environment to block LDAP requests to RODCs to avoid provisioning and password change errors.
  • Modify the network or directory settings to ensure that RODCs do not accept LDAP requests from the Okta AD Agent.

 

Related References

Loading
Okta Support - Read-Only Domain Controllers Cause Okta Active Directory Provisioning Errors