
NicolasR.94674 (Customer) asked a question.
Perform an AD Agent installation to sync Active Directory with Okta. I configured the Palo Alto Networks Global Protect application to implement a double authentication factor for SSL VPNs, however when I try to use the AD username and password to authenticate it does not work, I have tested with local Okta users and the access works without problems, I don't know what could be happening when using AD accounts

Hello @NicolasR.94674 (Customer) Thank you for reacting out to our Community!
You need to be sure that the username assigned to the Palo Alto application is the same as username you are trying for an AD user. I also recommend to review the Okta System logs and AD Agent logs to see what could be the issue and why it is not allowing you to properly sign in.
Please see our system log doc that could help you out in the troubleshooting:
https://help.okta.com/en-us/Content/Topics/Reports/syslog-filters.htm
Community members help others by clicking Like or Select as Best on responses. Try it today.
Watch and Learn: New Okta how-to videos, plus what's new this month in the May newsletter.
Hello @fzwcg (fzwcg)
Thanks in advance for the answer. But I have the following doubt, in addition to the implementation that I have already done, it is necessary to install another agent to synchronize AD passwords with Okta. As stated in the following link
https://help.okta.com/oie/en-us/Content/Topics/Directory/Installing_Configuring_Active_Directory_Password_Sync_Agent.htm?cshid=ad-pw-sync-agent
That should not be necessary, since AD would be the profile master Okta imports a hash of the password that is being used.
hello, @Paul S. (Okta, Inc.)
I appreciate your response and support with the link you send me to validate the error.