Manage Active Directory accounts

Early Access release

Okta Privileged Access Active Directory (AD) integration helps reduce the risks that are associated with undermanaged privileged AD accounts. This solution enables admins to discover and manage accounts and their passwords. It enforces access controls such as Role-Based Access Control (RBAC), MFA Access Requests, and time-limited check-out capabilities. It also offers an audit trail to support monitoring and compliance efforts.

Key capabilities

  • Connect to Active Directory environments using the existing Okta AD agent.

  • Discover privileged AD accounts and manage their passwords, requiring users to obtain them from Okta Privileged Access.

  • Create robust policies for accessing privileged AD accounts, such as requiring phishing-resistant MFA.

  • Require users to check out privileged AD account passwords. After a user checks in or the time limit expires, the passwords are automatically rotated. This prevents users from saving them.

  • Audit all admin and user activities.

Okta Active Directory agent

The AD agent is used to communicate with domains that manage AD account passwords within Okta Privileged Access. The AD agent must already be set up and integrated with Okta to enable the Okta Privileged Access AD account management features. See Manage your Active Directory integration.

The Okta AD agent service account must have permission to perform password resets on the accounts that are managed by Okta Privileged Access. See Grant Okta AD agent password management permissions.

Password rotation

Okta Privileged Access supports four types of Active Directory password rotation:

  • Automatic rotation: Passwords are automatically rotated when a user checks in an account or when a checkout time limit expires.

  • Scheduled rotation: Passwords rotate on a recurring schedule set at the project level. See Configure project settings for Active Directory accounts.

  • Manual rotation: Resource admins can rotate a single account password immediately by selecting Force a rotation from the actions menu for that account.

  • Manual bulk rotation: Resource admins can queue multiple account passwords for rotation in a single action. See Bulk rotate Active Directory passwords.

Account discovery and mapping

Okta Privileged Access discovers Active Directory accounts within admin-defined organizational units (OUs) and brings them under password management. A discovered AD account can be in one of two states, and Okta Privileged Access handles both automatically, with no admin setting required to choose between them:

  • AD-only account. The AD account has no corresponding Okta user. Okta Privileged Access manages the account's password directly, without creating or requiring an Okta user.

  • AD account linked to an Okta user. The AD account is already linked to an existing Okta user. Okta Privileged Access manages the account's password through that Okta user. The Okta user's status (Active, Suspended, or otherwise) is never changed as a result of Okta Privileged Access discovering, managing, or stopping management of the account.

If an AD-only account is later linked to a newly created or imported Okta user, Okta Privileged Access detects the link on its next discovery cycle and automatically switches to managing the account through that Okta user, with no admin action required.

When an account no longer matches an account rule and management stops:

  • If it was an AD-only account, Okta Privileged Access stops managing the password.

  • If it was an AD account linked to an Okta user, Okta Privileged Access stops managing the password. The Okta user is left exactly as it was. It isn't suspended or otherwise changed.