Active Directory Integration

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/39

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:41 PM on 12/9/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

40 Terms

1
New cards

Why should a company integrate Active Directory (AD) with Okta?

To provide centralized identity management, delegated authentication, user provisioning, password sync, and lifecycle automation.

2
New cards

What is the role of the Okta AD Agent in the integration process?

The Okta AD Agent is installed on-premises to facilitate user import, profile mastering, delegated authentication, and password synchronization.

3
New cards

What prerequisites are required for an Okta admin account to manage AD integration?

The Okta admin account must have permissions to manage application directory integration, manage agents, and register agents.

4
New cards

What permissions are required for the AD admin account to install the AD Agent?

Domain Admin is required to create the Okta service account automatically; alternatively, a Domain User with local administrator access can be used.

5
New cards

What are the requirements for the AD domain user that runs the Okta AD Agent service?

The user must be a member of Domain Users, have a password that never expires, and be dedicated to the Okta agent.

6
New cards

What are the first steps to install the Okta AD Agent?

Download the agent from Okta, install it on a Windows server, provide service account credentials, and register the agent with Okta.

7
New cards

What is the best practice for the number of AD agents to install for high availability?

Install at least two AD agents per domain on separate host servers to avoid a single point of failure.

8
New cards

What actions can an administrator take regarding agents in Okta?

An administrator can add agents, update agents, deactivate or delete agents, and manage auto-updates.

9
New cards

What happens to the AD user profile attributes upon integration with Okta?

Okta creates an AD User Profile with default and any custom attributes, auto-mapping many fields.

10
New cards

What is the difference between Scenario 1 and Scenario 2 for provisioning direction?

In Scenario 1, AD is the profile source with scheduled imports; in Scenario 2, an HR system is the source and supports creating/updating users in AD.

11
New cards

What are some testable topics for the OCA exam regarding Active Directory integration?

Expect questions on AD vs HR source of truth, agent installation requirements, service account permissions, auto-update constraints, provisioning direction, and preventing mass deletions.

12
New cards

What is JIT provisioning in the context of Active Directory integration with Okta?

JIT provisioning allows user accounts to be created in Okta upon their first login.

13
New cards
anki_ad_integration = """
14
New cards
Why integrate Active Directory with Okta?
To centralize user management and enable SSO and provisioning across cloud and on premises apps.
15
New cards
What component enables Okta to communicate with Active Directory?
The Okta AD Agent.
16
New cards
Where is the Okta AD Agent installed?
On a Windows server inside the corporate network.
17
New cards
Does the AD agent require inbound firewall ports?
No it uses outbound communication only.
18
New cards
What does delegated authentication allow?
AD authenticates the user when signing in to Okta.
19
New cards
What are two ways to bring AD users into Okta?
Scheduled import and JIT provisioning.
20
New cards
What Okta permissions are required to install and manage AD agents?
Manage application directory integration Manage agents and Register agents.
21
New cards
Why should you create custom admin roles for AD integration?
To enforce least privilege and limit permissions to AD administration.
22
New cards
What account is required if you want the installer to create the Okta service account?
An AD Domain Admin account.
23
New cards
If using an existing service account what permissions are required?
Local administrator on the host server and read access to OUs.
24
New cards
What group must the Okta service account belong to?
Domain Users.
25
New cards
What setting should the Okta service account have for its password?
Password never expires.
26
New cards
What utility allows you to manage the AD agent locally?
The Okta AD Agent Manager.
27
New cards
How many AD agents should be installed per domain for high availability?
At least two agents.
28
New cards
Why should all agents run the same version?
Mixed versions cause all agents to operate at the oldest agent’s capability level.
29
New cards
Where can you view and update AD agents in Okta?
Directory Integrations under the Active Directory integration Agents tab.
30
New cards
What does agent auto update require?
A minimum of two operational agents.
31
New cards
What profile does Okta create when integrating AD?
An Active Directory user profile.
32
New cards
What do AD to Okta provisioning settings control?
Import matching criteria JIT and whether AD can source Okta users.
33
New cards
What setting prevents mass deletion of users during import?
Halting imports that cause mass unassignments.
34
New cards
What must be enabled if an HR system is the master and Okta provisions to AD?
Create or link users in AD when assigned to the AD app.
35
New cards
What can Okta push to AD when Okta is the profile source?
Attribute updates user creation and user deactivation.
36
New cards
What does the Okta service account need for provisioning to AD?
Write permissions to specific AD objects.
37
New cards
What is required for delegated authentication?
Active Directory must authenticate the user through the AD agent.
38
New cards
When are AD passwords pushed to AD?
When Okta provisions a user and password sync is enabled.
39
New cards
"""
40
New cards