<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006t2yNSCAYOkta Classic EngineAdministrationAnswered2024-03-25T19:24:09.000Z2021-03-22T12:49:52.000Z2021-03-25T19:15:50.000Z

lezt0 (lezt0) asked a question.

Passwords set to expire at 90 days, Status is still active

Hello

All users have to reset their password after 90 days. If they do not, their status will go into Password_Expired. For some users, this is not happening. They are still logging in with their old password and their status is active. Why is this happening to some users and not others? What can be done to fix this?


  • User15779607611865471821 (Tier 2 - US East)

    Thank you for contacting Okta customer support! My name is Marcus and I'm with the Tier 2 Technical Support Engineering team.

     

    If you have users that are not applying to a 90 password expiration, it's important to note where the password is being sourced from - Active Directory, LDAP, etc. If the user is Okta mastered - perhaps they changed the password recently to reset that 90 expiration. You can review System Log for the past 3 months to see if there are any events where the user changed their password.

     

    Here are some System Log queries that can find this:

    • eventType eq "user.account.update_password" and target.id eq "user ID here"
    • eventType eq "system.agent.ad.reset_user_password" and target.id eq "user Id here"

     

    If the password is being sourced from a different directory like LDAP or AD, it's possible their profile is not properly linked to those sources anymore and will need to be confirmed in an import.

     

    This case might be best to open a Okta Support case to further investigate this.

    Expand Post
This question is closed.
Loading
Passwords set to expire at 90 days, Status is still active