<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Restoring Delegated Authentication for Okta Users After a Password Migration Campaign

Okta Classic Engine
Okta Identity Engine
Directories

Overview

During a password migration campaign, user authentication transitions from Active Directory (AD) to Okta, and Delegated Authentication is disabled on the AD instance when the campaign ends. Re-enabling Delegated Authentication and reimporting users from AD restores the feature and reverts authentication to AD via Delegated Authentication for those users.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory Integration
  • Delegated Authentication
  • Password Migration

Cause

When an administrator completes a password migration campaign, Delegated Authentication is disabled on the AD instance. Because the user accounts are now configured to authenticate with Okta, they will not authenticate via Delegated Authentication until the feature is re-enabled and the users are disconnected and reconnected to the AD instance through a reimport.

Solution

Re-Enabling Delegated Authentication on the AD Instance

Re-enable Delegated Authentication on the directory integration's Provisioning page to restore the feature for the AD instance.

  1. Navigate to the AD directory integration in the Admin Console.
  2. Go to Provisioning > Integration.
  3. Re-enable Delegated Authentication.

How Are Users Disconnected and Reconnected to the AD Instance?

Disconnect each affected user from the AD instance and then reimport and match them to restore Delegated Authentication at the user level.

  1. Navigate to the AD directory integration in the Admin Console.
  2. Select the Assignments tab of the directory integration.
  3. Remove each affected user from the Assignments tab to disconnect them from the AD instance.
  4. Go to Provisioning > To Okta and verify the user matching configuration in the User Creation & Matching section.
  5. Run a Full Import to reimport users from AD and match them to their Okta user accounts.
  6. If necessary, manually confirm the user matches following the import.

 

Related References

Loading
Restoring Delegated Authentication for Okta Users After a Password Migration Campaign | Okta Support