<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005lFTudSAGOkta Classic EngineUniversal DirectoryAnswered2026-04-01T09:00:20.000Z2018-12-04T07:21:41.000Z2019-04-08T00:06:19.000Z
  • Hello,

    If the user shows up as active in Okta but is locked out, please have a look at his profile in AD, the account is most likely locked in AD. His AD account will most likely say "Unlock account. This account is currently locked out on this Active Directory Domain Controller."

    Once the user is unlocked in AD they will be able to log into their account.

    You can also setup the Okta AD policy for users to self-service unlock their accounts from Security>Authentication>Active Directory Policy > Rule.

    Expand Post
  • t529b (t529b)

    Another option, assuming that you know the lockout threshold for your AD domain, is to set the lockout threshold in Okta (the one that pertains to Active Directory integrations) to a slightly lower threshold. By doing this, the user's Okta account will lock out before their AD account (assuming the lockout is caused by going over the lockout threshold in Okta, and not on some other system in your domain (outside of Okta)). Then you can unlock the user in Okta instead of AD.

    Expand Post
This question is closed.
Loading
AD Authenticated lock out