
User16380028103511751463 (Customer) asked a question.
We have Okta-AD integration setup with "Delegated Authentication" enabled. We are creating new users in Okta from HR source. As part of Joiner flow, we provision AD account through Okta. For Okta-AD integration, how we can set first time password for user account in AD?
Please let me know if you have any inputs/suggestions on this!

@User16380028103511751463 (Customer) Have you try enable password sync from okta to app for Active Directory integration.
Thanks for your response. This will work for setting password on AD, however this will not work with "Delegated Authentication" requirement. I think, there is no way we can just enable "Sync Password" for new user creation and make "Delegated Authentication" there after. That is the cache here. As per other post (https://support.okta.com/help/s/article/FirstTime-Login-For-Users-Pushed-from-Okta-to-Active-Directory?language=en_US), it is possible however to be handled in different way, outside AD provisioning
Hi, @User16380028103511751463 (Customer)
Thank you for posting on our Community page!
Delegated authentication maintains persistence for your directory authenticated (DelAuth) sessions and AD is maintained as the immediate and ultimate source for credential validation. As AD is responsible for authenticating users, changes to a user’s status (such as password changes or deactivations) are immediately pushed to Okta.
https://help.okta.com/en-us/Content/Topics/Directory/Directory_AD_Delegated_Authentication.htm
You can also check out this detailed article:
Thank you for reaching out to our Community and have a great day!
_____________________________________________________________________________
Community members help others by clicking Like or Select as Best on responses. Try it today.
_____________________________________________________________________________