
workspacest.33779 (Customer) asked a question.
Hi team,
I’m planning to integrate AWS WorkSpaces with Okta using SAML for authentication.
Architecture:
- AWS WorkSpaces (personal virtual desktops)
- AWS Directory Service (Microsoft AD) as the WorkSpaces directory
- Okta as IdP for SAML
- No RADIUS
I need clarification on two points:
- When is the Okta AD Agent generally required? ( My understanding: for AD user sync and delegated authentication.)
- Is the Okta AD Agent needed in my case, where:
- Users authenticate via Okta (IdP)
- AWS WorkSpaces uses AWS Directory Service (Microsoft AD) for directory backend
- SAML assertions must include correct attributes (e.g., userPrincipalName)
If the AD Agent is mainly for syncing users or delegated auth, and Okta handles auth, I assume it’s unnecessary. But since WorkSpaces relies on AD, is the agent still required for attribute resolution?
Any general explanation and guidance would be greatly appreciated!
Thanks!

Hi @workspacest.33779 (Customer) , Thank you for reaching out to the Okta Community!
Yes, the Okta AD Agent is still required in your scenario.
It acts as the bridge between your AWS Directory Service Microsoft AD and Okta. It is responsible for:
You will need to install and configure the Okta AD Agent on a Windows server (an EC2 instance, for example) that has network connectivity to your AWS Directory Service Microsoft AD and outbound access to Okta.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.