
lezt0 (lezt0) asked a question.
Hello
All users have to reset their password after 90 days. If they do not, their status will go into Password_Expired. For some users, this is not happening. They are still logging in with their old password and their status is active. Why is this happening to some users and not others? What can be done to fix this?

Thank you for contacting Okta customer support! My name is Marcus and I'm with the Tier 2 Technical Support Engineering team.
If you have users that are not applying to a 90 password expiration, it's important to note where the password is being sourced from - Active Directory, LDAP, etc. If the user is Okta mastered - perhaps they changed the password recently to reset that 90 expiration. You can review System Log for the past 3 months to see if there are any events where the user changed their password.
Here are some System Log queries that can find this:
If the password is being sourced from a different directory like LDAP or AD, it's possible their profile is not properly linked to those sources anymore and will need to be confirmed in an import.
This case might be best to open a Okta Support case to further investigate this.