Bulk rotate Active Directory passwords

Queue multiple Active Directory account passwords for rotation in a single action. After you queue accounts, a periodic job rotates them serially.

About this task

Early Access release

You can rotate passwords for multiple Active Directory accounts in a single operation. This reduces the time and effort required to manage credentials at scale, especially for compliance-driven rotation windows.

Before you begin

  • You must have an Okta Privileged Access resource admin role.

  • Review requirements and limitations and complete the required steps.

  • Accounts must not be in Rotating or Pending Rotation status to be queued for bulk rotation. Checked-out accounts can't be queued.

  1. On the Okta Privileged Access dashboard, go to Resource Administration > Resource assignment.
  2. Select one or more Active Directory accounts that you want to rotate. You can select up to 100 accounts in a single batch.
  3. Select Rotate password from the bulk actions menu.
  4. Review the accounts to be rotated, and select Confirm.

The selected accounts are now in Pending Rotation status and queued for rotation. When the bulk rotation job runs, it processes the accounts serially and updates their status to Rotated or Rotation Failed.

While an account is in Pending Rotation or Rotating status, users can't perform the following actions:

  • Check out the account

  • Reveal the account password

  • Manually rotate the password

To defer rotation or to clear a stalled queue, select the accounts in Pending Rotation status and select Cancel pending rotation from the bulk actions menu. The accounts revert to their previous status and are removed from the rotation queue.