<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5KZ00000vdMnq0AEOkta Classic EngineDirectoriesAnswered2025-06-11T07:13:07.000Z2025-06-09T04:57:07.000Z2025-06-11T07:13:07.000Z

ShoichiroK.00155 (LAC Co., Ltd) asked a question.

Okta Active Directory UnlockAccount

Is the delegated authentication function mandatory to enable a feature that allows users locked on the AD side to self-unlock on the Okta side?


  • Paul S. (Okta, Inc.)

    Hello @ShoichiroK.00155 (LAC Co., Ltd)​ Thank you for posting on our Community page!

     

    Yes, Delegated authentication is needed, you will also need a few additional settings for this to work, please see below:

    To enable self-service account unlock for AD-locked users via Okta, you need to:

     

    • Enable Delegated Authentication for your Active Directory integration in Okta.
    • Ensure your Okta AD Agent has the necessary permissions in Active Directory to unlock user accounts. This often requires elevated permissions for the service account running the Okta AD agent (e.g., Domain Admin, though specific, less privileged permissions might be possible depending on your AD setup and Okta version).
    • Configure the Okta Active Directory Policy to allow users to perform self-service account unlock.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @ShoichiroK.00155 (LAC Co., Ltd)​ Thank you for posting on our Community page!

     

    Yes, Delegated authentication is needed, you will also need a few additional settings for this to work, please see below:

    To enable self-service account unlock for AD-locked users via Okta, you need to:

     

    • Enable Delegated Authentication for your Active Directory integration in Okta.
    • Ensure your Okta AD Agent has the necessary permissions in Active Directory to unlock user accounts. This often requires elevated permissions for the service account running the Okta AD agent (e.g., Domain Admin, though specific, less privileged permissions might be possible depending on your AD setup and Okta version).
    • Configure the Okta Active Directory Policy to allow users to perform self-service account unlock.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Expand Post
    Selected as Best
This question is closed.
Loading
Okta Active Directory UnlockAccount