<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000AOhBbKSQVOkta Classic EngineAdministrationAnswered2026-04-01T09:00:20.000Z2021-02-04T16:00:33.000Z2021-02-08T13:20:17.000Z

DanM.34740 (Customer) asked a question.

HealthInsight recommendation not possible

HealthInsight tells me I have a weak policy:

  • Active Directory Policy is missing: lockout after unsuccessful attempts.

 

Except I go to this policy and there is no option to enable this option. The only lockout option is 'show lock out failures'. The default policy has this option but not the Active Directory Policy.

 

Am I missing something or is this a bug in HealthInsight?


  • k5fuw (k5fuw)

    There should be three checkboxes in the Lock out section of your Active Directory password policy, including the one that HealthInsight is referring to.

     

    Image is not available
    If you're not seeing all of those options, I would recommend opening a case with support. It's probably just a missing feature flag, and they can fix that sort of thing pretty quickly.

     

    I get that same warning from HealthInsight, but I ignore it because my Okta tenant is configured to delegate authentication to AD, and I want AD to control the user's account lockout state. In the past, I tried enabling this option in Okta but it actually caused more confusion for our Help Desk team because they needed to check for account lockouts in two locations (Okta AND Active Directory).

    Expand Post
  • DanM.34740 (Customer)

    Yeah, I don't have that. Will log a ticket with Support. Thanks for the reply.

This question is closed.
Loading
HealthInsight recommendation not possible