
AbouzeidE.18346 (Customer) asked a question.
I'm trying to evaluate whether it is best to install the AD Sync Agent or the Okta Password Sync Agent and whether the best practice is to install it on the domain controllers. Why would you do one or the other?

Hello @AbouzeidE.18346 (Customer) Thank you for posting on our Community page!
I am not sure what you are looking to achieve, however the Okta AD agent is needed to connect your AD domain with Okta Org. Note that the AD agent does need to be installed on the domain controler. The AD agent is basically the bridge between AD and Okta while the Password Sync agent is used to synchronize passwords from Active Directory (AD) to Okta and to integrated apps with password synchronization.
Please see our docs on both agents:
https://help.okta.com/en-us/content/topics/directory/ad-agent-prerequisites.htm
https://help.okta.com/en-us/content/topics/directory/installing_configuring_active_directory_password_sync_agent.htm
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.