<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7UeSSAVOkta Classic EngineAdministrationAnswered2024-04-17T11:14:15.000Z2015-12-07T19:44:12.000Z2018-03-26T23:53:20.000Z
Does Okta cache AD credentials for Active Directory Mastered accounts? If so, how?
Users have expressed concern over entering their AD credentials, which also provide VPN access to our internal infrastructure, into a web-based solution such as Okta.

 

How can I best explain to them the secure nature in which Okta handles the use of their AD credentials?

  • Raja Nejem - 1 (Okta, Inc.)

    ALL communication between Okta and the customer is protected by TLS 1.2 capable services supporting Perfect Forward Secrecy (PFS).  Okta supports Perfect Forward Secrecy (PFS) on all services which creates a unique TLS session key which means an attacker with Okta's private keys could not read previously captured traffic via sniffing or man-in-the-middle attacks.

     

    We create a very secure hash of the username, password and a unique user ID. This is salted and hashed with SHA256 in the same way Office 365 stores AD credential data. Note we do not just store your AD hash.
    Expand Post
  • mjpqt (mjpqt)

    Hi Raja.

     

    I had a couple of similar concerns from users and it is something that is a concern for me as well. Is there a white paper or any form of documentation that we can have access to, so that we can have a more detailed view?
  • Rocky (Customer)

    Is anyone still using Cisco VPN that uses AD credentials only? (no RSA token or other factor)
This question is closed.
Loading
Does Okta cache AD credentials for Active Directory Mastered accounts? If so, how?