<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007rFcxUCASOkta Identity EngineAuthenticationAnswered2025-10-11T09:00:47.000Z2022-07-28T22:10:39.000Z2022-07-29T17:07:13.000Z

owbwp (owbwp) asked a question.

Can Delegated Authentication Support Okta Mastered Users?

Hi,

 

Is it possible to have API as a master (Okta mastered) users who would be able to authenticate into Okta using Delegated Authentication (AD password)? Or is Delegated Authentication exclusive to only AD Mastered users? Delegated Auth would be the only thing we'd want to use the directory integration for.

 

Thanks!

 

Phil


  • b5n6c (b5n6c)

    Hi Philip Martinez ,

    The user will not be able to authenticate with their Active Directory password once their profile is disconnected from AD ( ie, becoming Okta masterded user) . Eventually the user has to reset the password to login to okta ..

  • owbwp (owbwp)

    Hi Jijo

     

    It appears possible if you uncheck Allow Active Directory to source Okta users.

     

    Here if a user gets created via JIT provisioning then they are Okta mastered, but the credential provider is AD. I've also noticed if you do API as a Master (Okta mastered) and you ensure it's Create User Without Credentials (Staged status) then if they do delegated authentication it appears at that point they too are Okta mastered with AD as the credential provider.

     

    If you use the API to try to create an activated user that's when delegated auth doesn't work.

    Image is not available
     

    Expand Post
This question is closed.
Loading
Can Delegated Authentication Support Okta Mastered Users?