<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Privileged Access Active Directory Integration Early Access Known Issues

Privileged Access
Okta Classic Engine
Okta Identity Engine

Overview

A known issue occurs in the Early Access release of Active Directory (AD) integration for Okta Privileged Access (OPA) when managing AD-sourced accounts as both Okta Service Accounts and OPA Imports. This conflict prevents Okta from bringing the accounts under management using an OPA AD account import rule. Remove the configuration of the targeted Okta service account or modify the rule to exclude the account to resolve the conflict.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Privileged Access (OPA)
  • Active Directory (AD) Integration

Cause

When administrators use OPA to manage and secure AD-sourced Okta user accounts as Okta service accounts, the configuration prevents Okta from bringing the accounts under management using an OPA AD account import rule. Similarly, if an AD account rule already manages an AD-sourced Okta user account, the rule prevents Okta from managing the account as an Okta service account.

Solution

How is the AD account management conflict resolved?

Resolve the management conflict by performing one of the following actions in the Okta Admin Console:

  • Remove the configuration of the Okta service account targeted by the AD rule.
  • Modify the AD rule so it does not target the Okta service account.
Loading
Okta Privileged Access Active Directory Integration Early Access Known Issues | Okta Support