
ShoichiroK.00155 (LAC Co., Ltd) asked a question.
Premise:
We are integrating Okta and Microsoft 365 (M365) using WS-Federation.
We are not using on-premises Active Directory (AD).
Devices are Entra Joined.
Question 1:
If a user wants to change their device password, is it possible to change the password from Okta and have it reflected?
Additionally, is the Okta Device Access license required?
Question 2:
Is it possible for users to change their password directly from their devices?
When I tried it, it displayed a message saying that password writeback is not enabled, so the change couldn't be made.
If anyone knows the answer, please let me know.

Hi @ShoichiroK.00155 (LAC Co., Ltd)
Since this is a cloud-only environment, when you federate Azure AD with Okta, Windows devices authenticate via Okta. For Azure AD–joined device sign-in, the Windows logon client uses WS-Trust (active federation) with Okta.
Users cannot change their password directly on the device (Ctrl+Alt+Del or Windows logon UI). All password changes must be performed through Okta’s self-service password change/reset flows.
Because Azure AD defers all authentication to Okta, the Okta password becomes the Windows login password. Changes in Okta are effective immediately for device sign-in and Microsoft 365 services.