<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Installing the Okta AD Agent Using a Group Managed Service Account (gMSA)

Okta Classic Engine
Okta Identity Engine
Directories

Overview

The Okta AD Agent supports the use of a Group Managed Service Account (gMSA), a specialized account type that automates password management for service accounts. Run the Okta AD Agent installer with a gMSA by entering the account name and leaving the password field empty, which resolves the need for manual password management.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta AD Agent
  • Group Managed Service Account (gMSA)
  • Active Directory (AD) Integration

Solution

What is the Okta Active Directory Agent installed using a Group Managed Service Account?

Follow Microsoft guidance to create and configure the gMSA for use on the server where the Okta AD Agent will be installed. For questions on gMSA configuration, contact Microsoft support. Ensure the gMSA is granted the necessary permissions for an Okta AD Agent service account, as described in About the AD Agent service account.

Once the gMSA is set up and configured for use on the server, run the Okta AD Agent installer as usual to complete the installation with the gMSA:

  1. Launch the Okta AD Agent installer.
  2. When prompted for the service account details, select Use an alternate account that I specify.
  3. Enter the gMSA account name, including a dollar sign at the end of the account name. For example: gMSA01$@example.com.
  4. Leave the password field empty.
  5. Click Next and continue the installation.

 

Related References

Loading
Installing the Okta AD Agent Using a Group Managed Service Account (gMSA) | Okta Support