<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Unable to Log Into Okta Using Temporary Active Directory Password
Administration
Okta Classic Engine
Directories
Okta Identity Engine
Overview

A user cannot log in to Okta using a temporary AD password when Delegated Authentication is enabled.

The following error appears on the login screen: 

 

Unable to sign in

 

Login - Unable to sign in

Applies To
  • Directories
  • Active Directory (AD)
  • Delegated Authentication
  • Password Policy
  • Okta Classic Engine
  • Okta Identity Engine (OIE)
Cause
  • The user's password is set to expire on the next login within Active Directory, and the Active Directory password policy rule in Okta does not allow users to change passwords.
  • The User must change password at next logon setting in Active Directory may also be set on the user.
Solution

Please follow the below video or steps: 



The user needs the ability to change their password from the Okta Login page.

  1. Grant users the ability to change their AD password through Okta:
  • If using the Okta Classic Engine, in the Okta Admin Console, navigate to Security > Authentication.
Authentication
  • If using OIE, select Security > Authenticators, then select Actions > Edit next to the Password authenticator.
Authentication
  1. In the left panel, select Active Directory Policy.
Authentication

 

  1. Scroll down to the Rules section, click the pencil icon next to the existing rule, or click Add Rule if only the default rule exists.
Add rule

 

  • In Classic, for THEN User can select change password, perform self-service password reset, and perform self-service account unlock.
Edit rule
  • In OIE, for THEN Users can perform self-service select Password change (from account settings), Password reset, and Unlock account. Also, ensure that a recovery method is selected.
Edit rule
  1. Ensure that the rule's status is Active.
Add rule
  1. Verify that the Password Settings in the Active Directory Password Policy in Okta match the password policy in Active Directory.
AD password policy
  1. Ensure the Okta service account has permission to change passwords in Active Directory. If permission changes are made, restart the Okta AD Agent service afterward.
Loading
Unable to Log Into Okta Using Temporary Active Directory Password