This article outlines a known issue with the Early Access release of Active Directory (AD) integration for Okta Privileged Access relating to managing AD-sourced accounts both as Okta Service Accounts and Okta Privileged Access (OPA) Imports.
- Okta Privileged Access - Active Directory Integration Early Access
-
When using OPA to manage and secure AD-sourced Okta user accounts as Okta service accounts, the accounts are prevented from being brought under management using an OPA AD account import rule until the Okta service account configuration is removed.
-
Similarly, if an AD-sourced Okta user account is already under OPA management via an import via AD account rule, this would prevent the account from being managed as an Okta service account.
To resolve the "Managing AD-sourced Accounts both as Okta Service Accounts and Okta Privileged Access (OPA) Imports" issue, remove the configuration of the Okta service account targeted by the AD rule via the Okta admin console or by changing the rule so it does not target that account.
