
llx2b (llx2b) asked a question.
We have no password expiration at the moment for Okta, we plan to turn it on. We DO, however, have password expiration in AD. Is there any linkage between the two? If someone's AD password expires before their Okta password does what is the behavior?

Hey Ryan,
For the scenario you are describing, it would matter if Delegated Authentication is ON, the password expiry is linked to AD if this is the case from Okta you will not expire the password, you can just send an email notification if you have the feature enabled, but the option Password expires is reserved to Okta cloud passwords only, for AD Policy's you'll only get the Prompt user X days before password expires with the Feature Flag enabled.
If they are totally separate, no Delegated Authentication, then there is certainly no need to have anything matching, but you can make the same expiry timer for Okta and AD. This would certainly depend on your Domain, actual password flow and your Security > Authentication > Password Policies
If you have anything specific you want to look into, just reach out to our Support Department and will gladly chime in.
Best Regards.