1/39
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Why should a company integrate Active Directory (AD) with Okta?
To provide centralized identity management, delegated authentication, user provisioning, password sync, and lifecycle automation.
What is the role of the Okta AD Agent in the integration process?
The Okta AD Agent is installed on-premises to facilitate user import, profile mastering, delegated authentication, and password synchronization.
What prerequisites are required for an Okta admin account to manage AD integration?
The Okta admin account must have permissions to manage application directory integration, manage agents, and register agents.
What permissions are required for the AD admin account to install the AD Agent?
Domain Admin is required to create the Okta service account automatically; alternatively, a Domain User with local administrator access can be used.
What are the requirements for the AD domain user that runs the Okta AD Agent service?
The user must be a member of Domain Users, have a password that never expires, and be dedicated to the Okta agent.
What are the first steps to install the Okta AD Agent?
Download the agent from Okta, install it on a Windows server, provide service account credentials, and register the agent with Okta.
What is the best practice for the number of AD agents to install for high availability?
Install at least two AD agents per domain on separate host servers to avoid a single point of failure.
What actions can an administrator take regarding agents in Okta?
An administrator can add agents, update agents, deactivate or delete agents, and manage auto-updates.
What happens to the AD user profile attributes upon integration with Okta?
Okta creates an AD User Profile with default and any custom attributes, auto-mapping many fields.
What is the difference between Scenario 1 and Scenario 2 for provisioning direction?
In Scenario 1, AD is the profile source with scheduled imports; in Scenario 2, an HR system is the source and supports creating/updating users in AD.
What are some testable topics for the OCA exam regarding Active Directory integration?
Expect questions on AD vs HR source of truth, agent installation requirements, service account permissions, auto-update constraints, provisioning direction, and preventing mass deletions.
What is JIT provisioning in the context of Active Directory integration with Okta?
JIT provisioning allows user accounts to be created in Okta upon their first login.