
kcmhc (kcmhc) asked a question.
the user has an expiring password. The Okta Dashboard will not allow the log in, the user tries the "Forgot password?" link.
that does not work.
The AD admin resets the user's AD password, and the user can access email, remote desktop, etc.
but can not sign into Okta again.
the user's account shows every attempt as failure: INVALID_CREDENTIALS

Hello @kcmhc (kcmhc) Thank you for reacting out to our Community!
After the password has been setup in AD, is the new password pushed to Okta? If this does not happen then this would be expected behaviour. You would need to trigger an import to retrieve the new password for the user or have JIT enabled so that when he logs in the new password will be pulled into Okta through JIT Update.
Community members help others by clicking Like or Select as Best on responses. Try it today.
Hey Paul, how does on confirm it is being pushed? How do I trigger an import and/or enable JIT?
thanks
You can see in the logs if the password has been updated for that user.
As for the settings for AD, please see this KB
https://help.okta.com/en-us/Content/Topics/Directory/ad-agent-configure-import.htm