
0d81x (0d81x) asked a question.
Our EMR provider uses OKTA currently hosted with a third party. They are migrating it in house. We currently have Okta agents on domain controllers and there is an AD account for this agent. In the current implementation we've added a custom AD attribute and they sync our AD users. We do all AD administration currently and OKTA just syncs. With the migration they are requesting to add the additional permissions shown in this document: https://help.okta.com/en-us/content/topics/directory/ad-agent-about-service-account.htm
I question if they need anything more than read permissions as that's what it is currently. The EMR provider has no need to create, delete or modify our AD users. Is there any other reason the Okta agent would need these additional permissions shown in the document linked above if they are just syncing with our AD for authentication?

@0d81x (0d81x) As far as I can see the write permissions are required for password management purposes not authentication and if you do not intend to manage passwords through Okta or allow self-service, then read-only should be enough.
Regards.
--
Join the discussion for Ask Me Anything on February 4, 2025: Advancements in Okta’s On-Prem Directory Integrations