
tdrp9 (tdrp9) asked a question.
Hi,
We want to change from delegate authentication (AD) to Sync password option (making the users use an Okta Password). When we change that, do the users need to define a new password or the password remains the AD password until the password expires?
We hope to not make all the users define a new password.
Thanks!

Which way do you want to use the sync? If you want to sync from Okta to AD then I think they will need to reset them, since there is currently no password in Okta if you're using delegated authentication back to AD. But if you're syncing from AD to Okta using the Password Sync Agent then those passwords should be there in AD and can be synced to Okta, right?
Okta to AD.
There is no way of avoiding all users to define an okta password ? I would like to pass from del auth (AD) to okta master (sync password option) without having to force every single user to define a new password.
For example, could I use the Password Sync Agent to create an okta password equal to AD password and then delete Password Sync Agent and Delegation authentication and activate Password Sync, in order to let okta manage the passwords? Or this process wouldn't work?
Thanks!
That might generally work, since as I mentioned above the Agent will sync the passwords from AD to Okta (so the password will be there), and then you can sync those Okta passwords back to AD, so they'll still have the same password they had for AD. But I think the timing might be tricky: you can't leave Delegated Auth on while you're using the Pwd Sync Agent. You'd need someone with more hands-on field experience (PS/partner/etc) to advise on whether this can work in practice and what the complexities might be.
Ok thanks!
I will open a ticket to get more informations about this workflow.
Just one last question, do you know if we can install Password Sync agent on a RODC? or should we installed only in Read and Write Domain Controllers?
Thanks!
The Password Sync agent is installed and configured on all domain controllers in each integrated domain in your forest: https://help.okta.com/en/prod/Content/Topics/Directory/Installing_Configuring_Active_Directory_Password_Sync_Agent.htm