Enable Active Directory delegated authentication

Use delegated authentication to enable self-service password resets for Active Directory (AD)-sourced users.

If you have the group password policy feature enabled, the self-service password reset settings are overridden and the fields aren't available.

When this feature is enabled, bulk password expiration includes AD-sourced users.

  1. In the Admin Console, go to DirectoryDirectory Integrations.
  2. Select an Active Directory instance.
  3. Click the Provisioning tab and select Integration in the Settings list.
  4. Scroll to the Delegated Authentication section and select Enable delegated authentication to Active Directory.
  5. Click Save.