<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Change the Service Account Password for Agentless Desktop Single Sign-on
Okta Classic Engine
Directories
Okta Identity Engine
Overview

This article provides the steps to update the service account's password for Agentless Desktop Single Sign-on.

Applies To
Solution

Follow the video or the steps below to update the password for the Agentless DSSO service account:


 

  1. Navigate to the account in Active Directory and change the password.
    1. Open Active Directory Users and Computers on the Domain Controller.
    2. Find and then right-click the service account.
    3. Choose Reset password.

"Reset password" option

  1. To validate the new credentials, log in to Okta.
    1. Go to Security > Delegated Authentication.
    2. Scroll to Agentless Desktop SSO.
    3. Click Edit.
    4. In the AD Instances section, select the Active Directory instance on which the SPN was configured.
    5. Click the pencil.

Edit button

    1. Enter the new password into the service account password field.
    2. Click Save to validate the new credentials.

Save the new credentials

NOTE: Users may be unable to sign in to Okta via Agentless DSSO if they received their Kerberos ticket before the service account had its password reset. The system log may display the following error: GSS_ERROR. To remediate this issue, simply log out of the domain (or log out of the domain-joined Windows computer) and re-authenticate. 
Loading
How to Change the Service Account Password for Agentless Desktop Single Sign-on