
StevenB.48057 (Customer) asked a question.
Is there any way to set up a dual direction password sync such that if IT resets the password for a user, the new password will be synchronized with OKTA while also enabling the user to reset their own password and have it sync back to AD for other AD based authentication such as RADIUS?

Yes Steven, you can do it by enabling 'delegated authentication to Active Directory' in the AD integration in Okta.
Hope this helps.
That's what we have on at the moment which, as I understand it, means all the password management happens on AD rather than in OKTA itself. However, when I try and test resetting a users password through email, the response I get just mentions using Windows to reset the password. Is there some other setting/change needed to enable a user reseting their own password through OKTA and having that password get pushed to AD?
You can try disabling the 'sync password' feature
That option was never enabled in the first place and can't be enabled while 'delegated authentication' is active and I can't turn off delegated auth since the AD Password Sync agent requires it.
Have you set 'Password is managed in Okta' under customization?
Yes, that's currently set
If you haven't already- under Auth->Self Password Reset Policy, check if the Authentication Provider is selected as Active Directory.
@StevenB.48057 (Customer) - Did you get the chance to check?
I did and it was already set. I did find the issue however, turns out you need to go to the OU's that you want to be able to reset their password and delegate control of them to the OktaService account.