<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008SINVvCAPOkta Classic EngineDirectoriesAnswered2024-02-07T16:30:02.000Z2022-11-28T19:12:54.000Z2022-11-28T20:04:29.000Z
  • DonF.81354 (Customer)

    Great question!

     

    Please see below for specs:

     

    image 

    A full set of prerequisites is listed below at the following link:

     

    Active Directory integration prerequisites

     

    This link provides a full list of requirements such as accounts, hardware, software, etc.

     

    Thanks!

     

    Expand Post
    • DulceS.07873 (Customer)

      Hi Don,

      Thank you for the documentation, but the link is the requirements to install the OKTA Agent.

      Our OKTA AD Agent will be installed on its own server but once installed, can the OKTA AD Agent talk to a Domain Controller running on Windows Server 2008? Does the OKTA Agent integrate with any Microsoft AD version that is in the same domain?

      Expand Post
      • DonF.81354 (Customer)

        Sure, so in your particular case, it sounds like the agent will be installed on perhaps Windows Server 2019, but the Domain Controller itself may be 2008.

         

        With that assumption out of the way, and assuming there are no compatibility issues that are associated with Microsoft's end of things, Okta does specify the following:

         

        image 

        As Okta does specify that the domain must be operating at the functional level of 2003 or higher, Microsoft states the below OS support this:

         

        imageSomething to keep in mind. Furthermore, Okta states that to enforce the AD Password Policy history, your functional level must be Windows Server 2012 R2 or higher.

         

        Microsoft states the following supports this:

        image 

        Therefore assuming this is something you want, you need to keep Microsoft's requirements in mind as well.

         

        At the end of the day, assuming you are on supported functional levels from Okta's perspective and you follow their requirements for the OS, and the OS is supported by Microsoft according to your functional level, you should be fine. Okta does recommend that you keep the same Okta agent version across all servers, but does not strictly speak to the requirement of those server OS's compared to the domain controller itself.

         

        Finally, while Okta recommends the agent is installed on a member server in the domain, you can install it on the domain controller itself. This would alleviate any issues/concerns with different OS versions across the domain.

         

        Thanks!

        Expand Post
This question is closed.
Loading
Microsoft Active Directory Version OKTA AD Agent Supports