<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y000091koO0SAIOkta Classic EngineAdministrationAnswered2024-04-15T10:51:08.000Z2020-08-26T14:58:12.000Z2020-09-03T07:18:00.000Z

9h7gy (9h7gy) asked a question.

AD integration "hardening"

good day: few weeks ago both of our AD agents stopped, and access to Okta was not possible, as expected. We would like to enhance this, and we have a couple of questions:

 

  1. is it possible to install the AD Agent on a Read Only Domain Controller?
  2. if we enable the AD password sync to Okta, would it be possible to log in Okta (and related Service Providers) even when our AD Agents are all KO?

 

Thanks in advance

Alessandro


  • User15926059059901035060 (Vendor Management)

    Hello Alessandro,

    Below you can find the answer to your questions:

     

    1. It is not supported to install the AD Agent on a Read Only Domain Controller. 

     

    2. It won't be possible if you are using the option Sync Password. If you want to log in to Okta when the AD agents are down you can use the option Delegated Authentication. "This feature will ensure that AD-mastered users will be able to access the Okta Dashboard for up to 5 days, with the following exceptions:

     

    - Lifecycle state change for the connected user (ie Suspend, Deactivate or Disable in a connected system like AD/LDAP)

    - A change to the connected Active Directory/LDAP users credentials (ie Password Change/Reset operations)

    - Time-based expiry of data in the cache. "

    https://support.okta.com/help/s/article/Cache-AD-Credentials-using-Delegated-Authentication?language=en_US 

    Expand Post
    Selected as Best
  • User15926059059901035060 (Vendor Management)

    Hello Alessandro,

    Below you can find the answer to your questions:

     

    1. It is not supported to install the AD Agent on a Read Only Domain Controller. 

     

    2. It won't be possible if you are using the option Sync Password. If you want to log in to Okta when the AD agents are down you can use the option Delegated Authentication. "This feature will ensure that AD-mastered users will be able to access the Okta Dashboard for up to 5 days, with the following exceptions:

     

    - Lifecycle state change for the connected user (ie Suspend, Deactivate or Disable in a connected system like AD/LDAP)

    - A change to the connected Active Directory/LDAP users credentials (ie Password Change/Reset operations)

    - Time-based expiry of data in the cache. "

    https://support.okta.com/help/s/article/Cache-AD-Credentials-using-Delegated-Authentication?language=en_US 

    Expand Post
    Selected as Best
This question is closed.
Loading
AD integration "hardening"