
Bertrand Djena.09958 (Customer) asked a question.
Okta and AD on premise Authentification
If anyone has a solution for this: Users log in via SSO to Okta, which delegates authentication to AD on-premise. Then they click on an application that they should normally be able to access directly without having to enter their password again, since they are already authenticated in Okta via SSO. However, Okta still asks them to enter a password to access that application. How can this be resolved? Thanks in advance.

Hello @Bertrand Djena.09958 (Customer) Thank you for posting on our Community page!
You are asking why users who have already authenticated to Okta via Single Sign-On (SSO) with Active Directory on-premises are still being prompted to enter their password when accessing applications they should be able to reach directly without re-authentication.
This typically occurs because the application's sign-on policy is configured to require password authentication, even when a valid Okta session already exists.
Root Cause:
The application's authentication policy is set to enforce password entry at the application level, overriding the existing Okta session. This can happen when:
Solution:
Follow these steps to allow users to access the application without re-entering their password:
If the application is a SAML or OpenID Connect application, verify that it is configured to accept the Okta session token and not to prompt for additional authentication. Some applications may have their own authentication settings that override Okta's session — check the application's configuration to ensure it trusts Okta's authentication.
Additional Considerations:
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.