<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00008vdEOUSA2Okta Classic EngineLifecycle ManagementAnswered2024-04-16T11:34:11.000Z2020-07-10T15:22:44.000Z2020-07-15T18:35:43.000Z

tdrp9 (tdrp9) asked a question.

Change from delegate authentication to Sync Password

Hi,

 

We want to change from delegate authentication (AD) to Sync password option (making the users use an Okta Password). When we change that, do the users need to define a new password or the password remains the AD password until the password expires?

 

We hope to not make all the users define a new password.

 

Thanks!


  • User15851122134349081871 (North Central-Enterprise)

    Which way do you want to use the sync? If you want to sync from Okta to AD then I think they will need to reset them, since there is currently no password in Okta if you're using delegated authentication back to AD. But if you're syncing from AD to Okta using the Password Sync Agent then those passwords should be there in AD and can be synced to Okta, right?

    Expand Post
  • tdrp9 (tdrp9)

    Okta to AD.

     

    There is no way of avoiding all users to define an okta password ? I would like to pass from del auth (AD) to okta master (sync password option) without having to force every single user to define a new password.

     

    For example, could I use the Password Sync Agent to create an okta password equal to AD password and then delete Password Sync Agent and Delegation authentication and activate Password Sync, in order to let okta manage the passwords? Or this process wouldn't work?

     

    Thanks!

    Expand Post
    • User15851122134349081871 (North Central-Enterprise)

      That might generally work, since as I mentioned above the Agent will sync the passwords from AD to Okta (so the password will be there), and then you can sync those Okta passwords back to AD, so they'll still have the same password they had for AD. But I think the timing might be tricky: you can't leave Delegated Auth on while you're using the Pwd Sync Agent. You'd need someone with more hands-on field experience (PS/partner/etc) to advise on whether this can work in practice and what the complexities might be.

      Expand Post
This question is closed.
Loading
Change from delegate authentication to Sync Password