Okta Privileged Access Active Directory Integration Early Access Known Issues
Last Updated:
Overview
A known issue occurs in the Early Access release of Active Directory (AD) integration for Okta Privileged Access (OPA) when managing AD-sourced accounts as both Okta Service Accounts and OPA Imports. This conflict prevents Okta from bringing the accounts under management using an OPA AD account import rule. Remove the configuration of the targeted Okta service account or modify the rule to exclude the account to resolve the conflict.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Privileged Access (OPA)
- Active Directory (AD) Integration
Cause
When administrators use OPA to manage and secure AD-sourced Okta user accounts as Okta service accounts, the configuration prevents Okta from bringing the accounts under management using an OPA AD account import rule. Similarly, if an AD account rule already manages an AD-sourced Okta user account, the rule prevents Okta from managing the account as an Okta service account.
Solution
How is the AD account management conflict resolved?
Resolve the management conflict by performing one of the following actions in the Okta Admin Console:
- Remove the configuration of the Okta service account targeted by the AD rule.
- Modify the AD rule so it does not target the Okta service account.
