
9h7gy (9h7gy) asked a question.
good day: few weeks ago both of our AD agents stopped, and access to Okta was not possible, as expected. We would like to enhance this, and we have a couple of questions:
- is it possible to install the AD Agent on a Read Only Domain Controller?
- if we enable the AD password sync to Okta, would it be possible to log in Okta (and related Service Providers) even when our AD Agents are all KO?
Thanks in advance
Alessandro

Hello Alessandro,
Below you can find the answer to your questions:
1. It is not supported to install the AD Agent on a Read Only Domain Controller.
2. It won't be possible if you are using the option Sync Password. If you want to log in to Okta when the AD agents are down you can use the option Delegated Authentication. "This feature will ensure that AD-mastered users will be able to access the Okta Dashboard for up to 5 days, with the following exceptions:
- Lifecycle state change for the connected user (ie Suspend, Deactivate or Disable in a connected system like AD/LDAP)
- A change to the connected Active Directory/LDAP users credentials (ie Password Change/Reset operations)
- Time-based expiry of data in the cache. "
https://support.okta.com/help/s/article/Cache-AD-Credentials-using-Delegated-Authentication?language=en_US