<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007pKmN7CAKOkta Classic EngineSingle Sign-OnAnswered2026-04-01T09:00:20.000Z2022-07-19T12:55:47.000Z2022-07-22T19:26:10.000Z
Agentless desktop SSO GPO for encryption - Only required on OKTA AD Agent member server or all computers and DC on domain?

I am in the process of setting up agentless desktop SSO and following the below guide.

https://help.okta.com/en-us/Content/Topics/Directory/ad-dsso-create-service-account.htm

 

I have a question on step 9. Specifically this statement "The group policy can be created on the domain controller, or on the server where the Okta AD Agent is installed. The policy is applied to the entire domain and applies to all domain servers and workstations within the domain."

 

Does this mean I only need to create the group policy to enable the additional encryptions on just the member server where the OKTA AD agent is installed? Or does it need to be applied to all computers and domain controllers on the domain? I prefer to just do it on the OKTA AD Agent server.


  • k5fuw (k5fuw)

    Step 9 is poorly worded, and hopefully no one is installing the AD agent on their domain controller. That's just very bad practice.

     

    The policy must be applied to all machines in the domain. In many cases, the Group Policy Management Console is only installed on a domain controller, so that's where the policy would be created. But it is possible to install the add-in on a member server and create the policy there, but it's still a domain policy, not just local to the member server where the AD agent is installed.

    Expand Post
This question is closed.
Loading
Agentless desktop SSO GPO for encryption - Only required on OKTA AD Agent member server or all computers and DC on domain?