<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z000079hTg3CAEOkta Classic EngineAuthenticationAnswered2024-04-30T09:27:15.000Z2021-09-02T14:25:11.000Z2021-09-06T21:07:20.000Z

SteveB.25212 (Fidelity Life) asked a question.

OKTA to AD Password Sync

Currently my organization has Active Directory setup as the primary source of truth for all user data including password.

 

We want to setup OKTA to manage our password resets. I understand this is a supported feature, however I am concerned about some possible problems with this implementation.

 

Based on what I read here https://help.okta.com/en/prod/Content/Topics/Directory/Security_Using_Sync_Password.htm the process of enabling OKTA to AD sync is incredibly easy, however it does not answer 1 critical question.

 

If almost ALL of my OKTA users were originally sourced from AD and the ONLY password they have is via AD, will their password remain the same after I enabled OKTA to AD sync.

 

For example in this scenario:

  1. John Smith is created in AD
  2. AD syncs account to OKTA
  3. AD syncs account to Office365 for email account creation
  4. John Smith logs into OKTA using his AD account password of "SuperSecretPassword1234"
  5. I disable delegated authentication,
  6. When presented with the "Disable Active Directory Authentication" pop up I select 'DON'T create Okta password.' /help/servlet/rtaImage?refid=0EM4z0000027NuA
  7. I enable Password sync from OKTA to AD.

 

Can John Smith still login to:

  1. Can John Smith still login to OKTA in this scenario using the password "SuperSecretPassword1234"?
  2. Can John Smith still login to his email using that same password?
  3. Can John Smith still login to his computer with that same password?
  4. Can I as the admin still login to OKTA using my previous AD password or do I have to click the "Create OKTA password" option in order to be able to stay logged in and to have access to OKTA?

 

Thanks in advance to any help anyone can provide.


  • dn0il (dn0il)

    Hi Steve,

     

    Reading your question (...We want to setup OKTA to manage our password resets) it can lead to think that you want AD users to reset their AD password using Okta, this can be done and here is the document on how to accomplish that:

     

    https://help.okta.com/en/prod/Content/Topics/users-groups-profiles/usgp-manage-password-reset.htm

     

    Assuming that what you want is users to change their password in Okta and push that password to AD, here are the answers:

     

    If almost ALL of my OKTA users were originally sourced from AD and the ONLY password they have is via AD, will their password remain the same after I enabled OKTA to AD sync?

     

    As the document mentions, you need to disable delegated authentication (DelAuth) in order for Okta to AD password sync to work. When you have DelAuth enabled, there is no Okta password because the password used to login to Okta is the AD password, this being said, after you enabled OKTA to AD sync, the AD password will no longer allow access to Okta and you will need to reset the Okta password for the users. New Okta password will be pushed to AD.

     

    To reply some questions in your scenario:

     

    1. Can John Smith still login to OKTA in this scenario using the password "SuperSecretPassword1234"? No, the user will need to reset his Okta password.
    2. Can John Smith still login to his email using that same password? Yes, assuming they can access Okta and login to his email via an app in their Okta dashboard.
    3. Can John Smith still login to his computer with that same password? Yes, after you disconnect the user from AD, the AD password will remain working until you trigger a password change from Okta, in this case, new Okta password will be AD's password.
    4. Can I as the admin still login to OKTA using my previous AD password or do I have to click the "Create OKTA password" option in order to be able to stay logged in and to have access to OKTA? If your account was AD-mastered and you disconnected it from AD, No, you will need to reset your Okta password because the AD password will only work to access AD until it is reset from Okta.

     

    If you have further questions please open a support case.

     

    Thank You,

     

    Jonathan - Okta Global Customer Care

    Expand Post
This question is closed.
Loading
OKTA to AD Password Sync