<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Resolve Okta Password Expiration Alerts for Microsoft Single Sign-On Users

Okta Classic Engine
Okta Identity Engine
Administration

Overview

When an organization utilizes Microsoft Single Sign-On (SSO) as the primary Identity Provider (IdP) for Okta, alerts indicating that federated users have pending password reset flags or expiring credentials may occur. This conflict happens because legacy Okta password policies still apply to users' local shadow profiles. Resolve these alerts by creating and applying a dedicated Okta password policy that disables password expiration for this specific population.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Microsoft Entra ID (SSO)
  • Federated User Management

Cause

Legacy Okta password policies may still apply to users' local shadow profiles, even though Microsoft SSO handles the actual authentication exclusively.

Solution

How are Okta password expiration alerts resolved for Microsoft Single Sign-On users?

Prevent local password expiration requirements from impacting SSO-only users by creating and applying a dedicated Okta password policy that disables password expiration for this specific population.

  1. Log in to the Okta Admin Console and navigate to Security > Authenticators (or Security > Authentication, depending on the tenant version).
  2. On the Setup tab (or Password tab), select the option to Add New Password Policy, or click Actions > Edit on the existing Password item.
  3. Complete the required fields by providing a unique policy name and description.
  4. In the Add group field, enter and select the specific groups that contain the Microsoft SSO federated user population.
  5. Under the password age and expiration settings, locate the Password expires after configuration.
  6. Adjust this setting so that the password does not expire.
  7. Save the policy.
  8. Ensure the policy is prioritized correctly in the policy list so that it successfully overrides any legacy rules for the federated users.

 

NOTE: Test the new policy in a non-production environment before implementing it broadly across a production tenant.

 

Loading
Resolve Okta Password Expiration Alerts for Microsoft Single Sign-On Users | Okta Support