
owbwp (owbwp) asked a question.
Hi,
Is it possible to have API as a master (Okta mastered) users who would be able to authenticate into Okta using Delegated Authentication (AD password)? Or is Delegated Authentication exclusive to only AD Mastered users? Delegated Auth would be the only thing we'd want to use the directory integration for.
Thanks!
Phil

Hi Philip Martinez ,
The user will not be able to authenticate with their Active Directory password once their profile is disconnected from AD ( ie, becoming Okta masterded user) . Eventually the user has to reset the password to login to okta ..
Hi Jijo
It appears possible if you uncheck Allow Active Directory to source Okta users.
Here if a user gets created via JIT provisioning then they are Okta mastered, but the credential provider is AD. I've also noticed if you do API as a Master (Okta mastered) and you ensure it's Create User Without Credentials (Staged status) then if they do delegated authentication it appears at that point they too are Okta mastered with AD as the credential provider.
If you use the API to try to create an activated user that's when delegated auth doesn't work.