Resolve Okta Password Expiration Alerts for Microsoft Single Sign-On Users
Last Updated:
Overview
When an organization utilizes Microsoft Single Sign-On (SSO) as the primary Identity Provider (IdP) for Okta, alerts indicating that federated users have pending password reset flags or expiring credentials may occur. This conflict happens because legacy Okta password policies still apply to users' local shadow profiles. Resolve these alerts by creating and applying a dedicated Okta password policy that disables password expiration for this specific population.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Entra ID (SSO)
- Federated User Management
Cause
Legacy Okta password policies may still apply to users' local shadow profiles, even though Microsoft SSO handles the actual authentication exclusively.
Solution
How are Okta password expiration alerts resolved for Microsoft Single Sign-On users?
Prevent local password expiration requirements from impacting SSO-only users by creating and applying a dedicated Okta password policy that disables password expiration for this specific population.
- Log in to the Okta Admin Console and navigate to Security > Authenticators (or Security > Authentication, depending on the tenant version).
- On the Setup tab (or Password tab), select the option to Add New Password Policy, or click Actions > Edit on the existing Password item.
- Complete the required fields by providing a unique policy name and description.
- In the Add group field, enter and select the specific groups that contain the Microsoft SSO federated user population.
- Under the password age and expiration settings, locate the Password expires after configuration.
- Adjust this setting so that the password does not expire.
- Save the policy.
- Ensure the policy is prioritized correctly in the policy list so that it successfully overrides any legacy rules for the federated users.
NOTE: Test the new policy in a non-production environment before implementing it broadly across a production tenant.
