Okta Application Password Synchronization Fails With Desktop Single Sign-On
Last Updated:
Overview
Application password synchronization from Okta to a downstream application requires manual credential entry to function. When users authenticate using Agentless Desktop Single Sign-On (ADSSO) or Integrated Web Authentication (IWA), Okta bypasses manual credential entry, preventing the password synchronization process. The observable issue occurs when an administrator configures password synchronization to a downstream application, but the password fails to synchronize after a user authenticates via ADSSO or IWA.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Agentless Desktop Single Sign-On (ADSSO)
- Integrated Web Authentication (IWA)
- Application Password Synchronization
Cause
Agentless Desktop Single Sign-On and Integrated Web Authentication authenticate users without requiring manual credential entry. Application password synchronization requires Okta to capture the user credentials during the login process to push them to the downstream application.
Solution
Why does password synchronization fail during desktop single sign-on?
This is expected behavior. Okta requires the user to manually enter their credentials during the login process to trigger application password synchronization. If a user authenticates via ADSSO or IWA, Okta does not capture the password, and the synchronization to the downstream application does not occur. The user must log in to Okta with their credentials to synchronize the password.
