<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008wsY33CAEOkta Classic EngineSingle Sign-OnAnswered2025-09-28T09:01:18.000Z2023-03-16T19:05:19.000Z2023-03-17T22:49:19.000Z

kcmhc (kcmhc) asked a question.

okta user attempts AD password reset "Forgot password?" then failure: INVALID_CREDENTIALS

the user has an expiring password. The Okta Dashboard will not allow the log in, the user tries the "Forgot password?" link.

that does not work.

The AD admin resets the user's AD password, and the user can access email, remote desktop, etc.

but can not sign into Okta again.

the user's account shows every attempt as failure: INVALID_CREDENTIALS


  • Hello @kcmhc (kcmhc)​ Thank you for reacting out to our Community!

     

    After the password has been setup in AD, is the new password pushed to Okta? If this does not happen then this would be expected behaviour. You would need to trigger an import to retrieve the new password for the user or have JIT enabled so that when he logs in the new password will be pulled into Okta through JIT Update.

     

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
  • kcmhc (kcmhc)

    Hey Paul, how does on confirm it is being pushed? How do I trigger an import and/or enable JIT?

    thanks

This question is closed.
Loading
okta user attempts AD password reset "Forgot password?" then failure: INVALID_CREDENTIALS