NickT.68327 (Customer) asked a question.
Do I need to delegate rights in AD for users to be able to unlock accounts in order for the Okta self service unlock to work? Currently, it goes through the motions, i enter username or email, select SMS, I get the message, enter the code, and it replies successful, but the AD account never actually unlocks.
Security > Authentication > Rules
We have a rule that allows all 3 forms of self service
Security > Authentication > Unlock
We have unlock okta and active directory


A locked account in AD won't automatically propagate to be a locked account in Okta. This is one of the cases for why some people use delegated authentication: then if the AD account is locked out they won't be able to authenticate in Okta.