Restoring Delegated Authentication for Okta Users After a Password Migration Campaign
Last Updated:
Overview
During a password migration campaign, user authentication transitions from Active Directory (AD) to Okta, and Delegated Authentication is disabled on the AD instance when the campaign ends. Re-enabling Delegated Authentication and reimporting users from AD restores the feature and reverts authentication to AD via Delegated Authentication for those users.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory Integration
- Delegated Authentication
- Password Migration
Cause
When an administrator completes a password migration campaign, Delegated Authentication is disabled on the AD instance. Because the user accounts are now configured to authenticate with Okta, they will not authenticate via Delegated Authentication until the feature is re-enabled and the users are disconnected and reconnected to the AD instance through a reimport.
Solution
Re-Enabling Delegated Authentication on the AD Instance
Re-enable Delegated Authentication on the directory integration's Provisioning page to restore the feature for the AD instance.
- Navigate to the AD directory integration in the Admin Console.
- Go to Provisioning > Integration.
- Re-enable Delegated Authentication.
How Are Users Disconnected and Reconnected to the AD Instance?
Disconnect each affected user from the AD instance and then reimport and match them to restore Delegated Authentication at the user level.
- Navigate to the AD directory integration in the Admin Console.
- Select the Assignments tab of the directory integration.
- Remove each affected user from the Assignments tab to disconnect them from the AD instance.
- Go to Provisioning > To Okta and verify the user matching configuration in the User Creation & Matching section.
- Run a Full Import to reimport users from AD and match them to their Okta user accounts.
- If necessary, manually confirm the user matches following the import.
