Active Directory integration implementation options

How you implement your Okta Active Directory (AD) integration is dependent on the size of your organization, your business requirements, and the scope of your deployment. There are two options:

  • Proof of Concept (POC) or simple deployment — If you're doing a POC or a simple AD integration, you'll probably want to install the Okta AD Agent, import some users, and configure basic settings. You may not need high availability (HA) or disaster recovery (DR) options, or be concerned about the attributes you import from your AD user profiles into Okta.
  • Large scale enterprise deployment — For large enterprise deployments, it is likely that you'll want to do some planning before installing the Okta AD Agent and importing user data.

You can adjust your configuration options and make changes as your implementation evolves. These topics can help you plan your implementation:

These diagrams illustrate the two most common AD integration scenarios.

AD single forest and single domain deployment

AD single forest and multiple domain deployment