
8rw9f (8rw9f) asked a question.
I have found Okta Directory synchronization/integration with on-premises Active Directory; however, have had a very hard time finding integration instructions with Azure Active Directory (AAD in cloud).
I thought I had read there was an "agent-less" configuration for AAD but have not found any supporting documentation on setting this up.

Hi Gregory!
I'm happy to share some documentation scoped around this topic.
We typically do not have a direct integration path for this but these links I found may be a very helpful place to start:
Azure AD federation compatibility list ( https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-compatibility )
Azure AD as Federation Provider for Okta ( https://stackoverflow.com/questions/34297152/azure-ad-as-federation-provider-for-okta%E2%80%8B )
Also, our Professional Services ( https://www.okta.com/services/professional-services/ ) team can also help build out these types of integrations as well (as just another option).
Please let me know if you have any other questions, I'm glad to help.
All the best,
Mihail
It seems to me you guys could provide a bit more information in this topic. What you have provided is two links to off-site articles and a professional services link. There are likely a huge number of organizations who would like to create a two-way binding between the Azure AD and OKTA.
I can only guess based on the answers here that:
In either case, the responsible thing to do would be to bring in your top people to write up a detailed guide explaining the process, pros, cons, etc. I registered with OKTA just now and of course my first task it to attempt to sync my AzureAD with OKTA. I'm about to dig into these links, but am pretty surprised by the lack of documentation on this topic.
Totally agree... where is the "easy" how-to guide? Even if not easy, at least Okta based documentation would be ideal!
I agree with the OP that a step by step guide would be useful.
I found the following link https://www.okta.com/partners/microsoft/azure-active-directory/ but it seems more like marketing material rather than useful documentation for us to use.
I would also like to know how to take AAD mastered users and get those accounts to work in Okta. We have done it with on-prem AD using the agent. How do we do the same for AAD?
We currently use Okta that integrates with On-prem AD. We suffered a complete internet outage (almost 12 hours) last week and things did not work right with Okta not being able to communicate to the on-prem Ad (lots of login issues for folks that were not onsite). I have been asked to explore adding AD in the cloud (Azure AD I presume) as a secondary authentication source. Is this even possible??
We are in same situation. We actually used OKTA Pro Services and are still having issues syncing groups from local AD to AAD, etc. So we have reengaged and I will post how it works out. there is too much "fine print" in these deployments vs the bold statements in OKTA advertisement material. Don't get me wrong, both OKTA support and OKTA Pro Services have been nothing but professional and great to work with.. i would just say there should be more material available to end users in premier contracts.
We just purchase Okta Lifecycle component with the intention of using Okta to master profiles (provision users) into Azure AD. I don't even know where to start on this. I thought about adding the Microsoft 365 application (since it uses Azure AD) but that didn't work (probably because we don't really have Microsoft 365 subscription; just Azure AD). I'm not asking for a step by step guide but any tips on where I should start?
Agree. I have looked at several times and don't really know where to start and the lack of documentation on it seems to point out this there is some underlying issue for this.
I've just gone through the same nightmare of trying to find a guide on how to do this. This blog was very useful. If you have any questions, I'm happy to try and help.