VanH.30758 (Lytx, Inc.) asked a question.
Hello all,
Our tenant is currently profile mastered by Workday and Active Directory (with Workday being the top level master).
We want people to be able to do self-service password resets and unlocks through OKTA. Does anyone know if this is possible and if so, would you be able to point me towards any technical documentation? I haven't had luck finding it myself.
Thank you!

Hello Van,
Profile mastery won't be impactful to whether user's can perform a self-service password reset. It's a pretty long read, but much of the configuration items you'll need to look at are covered in the following documentation:
help.okta.com/en/prod/Content/Topics/Security/Security_Policies.htm
Ultimately, you'll probably want to navigate over to Security > Authentication > Password (default tab), where you'll see your password policies. There will be an "account recovery" section, and if you add a rule to the policy, there will be options to allow: change password, perform self-service password reset, and perform self-service account unlock. Configuring this is typically sufficient if the passwords are managed by Okta.
However, if you are using delegated authentication to Active Directory, the in addition to performing the above configuration, you'll also need to ensure your service account that runs the Okta AD Agent has sufficient permissions in AD to actually change the passwords of users in AD.