<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00002AAxBy0ALOkta Classic EngineAuthenticationAnswered2026-09-21T22:33:22.000Z2026-09-21T21:59:46.000Z2026-09-21T22:32:14.000Z

Bertrand Djena.09958 (Customer) asked a question.

Okta and AD on premise Authentification

If anyone has a solution for this: Users log in via SSO to Okta, which delegates authentication to AD on-premise. Then they click on an application that they should normally be able to access directly without having to enter their password again, since they are already authenticated in Okta via SSO. However, Okta still asks them to enter a password to access that application. How can this be resolved? Thanks in advance.

 


  • Paul S. (Okta, Inc.)

    Hello @Bertrand Djena.09958 (Customer)​ Thank you for posting on our Community page!

     

    You are asking why users who have already authenticated to Okta via Single Sign-On (SSO) with Active Directory on-premises are still being prompted to enter their password when accessing applications they should be able to reach directly without re-authentication.

     

    This typically occurs because the application's sign-on policy is configured to require password authentication, even when a valid Okta session already exists.

     

    Root Cause:

    The application's authentication policy is set to enforce password entry at the application level, overriding the existing Okta session. This can happen when:

    • The application's sign-on policy is configured to always require password authentication (not delegating to the existing Okta session).
    • The application is not configured to use the Okta session token for seamless access.
    • The authentication policy rule is set to "Prompt for Factor" or a similar enforcement that bypasses session reuse.

     

    Solution:

    Follow these steps to allow users to access the application without re-entering their password:

    1. Sign in to the Okta Admin Console as an administrator.
    2. Navigate to Applications → Applications and locate the application in question.
    3. Click the application name to open its configuration.
    4. Select the Sign On tab.
    5. Review the Sign-On Policy section. Look for any rules that require password authentication or additional factors.
    6. Modify the sign-on policy rule to remove or adjust the password requirement. Ensure the rule allows users with an active Okta session to proceed without additional authentication prompts.
    7. Check that the application's authentication method is set to use Okta's session token (typically labeled as "Okta" or "SAML 2.0" depending on the app type) rather than requiring direct credential entry.
    8. Save your changes.
    9. Test by having a user log in via SSO and then access the application without logging out of Okta. They should not be prompted for a password.

     

    If the application is a SAML or OpenID Connect application, verify that it is configured to accept the Okta session token and not to prompt for additional authentication. Some applications may have their own authentication settings that override Okta's session — check the application's configuration to ensure it trusts Okta's authentication.

     

    Additional Considerations:

    • If the application requires step-up authentication (additional verification for sensitive operations), that is expected behavior and is separate from the initial application access.
    • Ensure that the user's group membership and application assignment are correct, as access restrictions can sometimes trigger re-authentication prompts.
    • If using Okta's Universal Login, verify that the application is configured to redirect through Universal Login rather than directly to the application's login page.

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post

Loading
Okta and AD on premise Authentification