<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006eqcGOSAYOkta Classic EngineIntegrationsAnswered2026-05-29T09:00:20.000Z2019-09-13T18:49:16.000Z2019-10-24T18:31:31.000Z

llx2b (llx2b) asked a question.

Is AD Password Expiration date pushed to Okta

We have no password expiration at the moment for Okta, we plan to turn it on. We DO, however, have password expiration in AD. Is there any linkage between the two? If someone's AD password expires before their Okta password does what is the behavior?


  • Hey Ryan,

     

    For the scenario you are describing, it would matter if Delegated Authentication is ON, the password expiry is linked to AD if this is the case from Okta you will not expire the password, you can just send an email notification if you have the feature enabled, but the option Password expires is reserved to Okta cloud passwords only, for AD Policy's you'll only get the Prompt user X days before password expires with the Feature Flag enabled.

    If they are totally separate, no Delegated Authentication, then there is certainly no need to have anything matching, but you can make the same expiry timer for Okta and AD. This would certainly depend on your Domain, actual password flow and your Security > Authentication > Password Policies

    If you have anything specific you want to look into, just reach out to our Support Department and will gladly chime in.

     

    Best Regards.

     

    Expand Post
    Selected as Best
  • llx2b (llx2b)

    We are NOT using JIT as our users are mastered in Okta.

  • Hey Ryan,

     

    For the scenario you are describing, it would matter if Delegated Authentication is ON, the password expiry is linked to AD if this is the case from Okta you will not expire the password, you can just send an email notification if you have the feature enabled, but the option Password expires is reserved to Okta cloud passwords only, for AD Policy's you'll only get the Prompt user X days before password expires with the Feature Flag enabled.

    If they are totally separate, no Delegated Authentication, then there is certainly no need to have anything matching, but you can make the same expiry timer for Okta and AD. This would certainly depend on your Domain, actual password flow and your Security > Authentication > Password Policies

    If you have anything specific you want to look into, just reach out to our Support Department and will gladly chime in.

     

    Best Regards.

     

    Expand Post
    Selected as Best
This question is closed.
Loading
Is AD Password Expiration date pushed to Okta