
susab (susab) asked a question.
If a user is locked out of Active Dir, and therefore cannot log into their domain computer, how can they unlock their AD account utilizing Okta? In a sense, it is typically done with a PSS product and the Windows Gina. If locked out of AD, they cannot gain access to to their Okta org to unlock AD account.

Hi Larry, this sounds frustrating. I've asked my support team colleagues to look into this and help out.
In the meantime, wondering if anyone else here in the Community has solved this problem, and can share the solution?
Thank you!
Larry Cortez
Sent with BlackBerry Work
(www.blackberry.com)
Hi Larry,
Yes this is possible via OKTA. You can setup self service account unlock via OKTA for AD accounts from your Admin console -> Security > Authentication > Active Directory-> Scroll Down and edit the Legacy rule to allow Self service account unlock. I added the Okta security policies documentation below:
https://help.okta.com/en/prod/Content/Topics/Security/Security_Policies.htm
We also have a softlock feature. For AD-mastered users, Okta provides a Softlock feature, used in conjunction with AD to prevent end-user lockouts. Previously, repeatedly entering an invalid password during Okta login could lock an end-user out of their Windows account and hardware device. This option also prevents a malicious third party from using Okta to lock up an end user via the web.
Documentation below:
https://support.okta.com/help/s/article/How-does-the-password-policy-soft-lock-functionality-work