Okta Privileged Access Fails To Discover Active Directory Shared Accounts
Last Updated:
Overview
Okta Privileged Access (OPA) fails to discover Active Directory (AD) shared accounts in a configured Organizational Unit (OU) after creating a Shared Account Rule. This occurs when the Active Directory integration lacks the selected Organizational Unit for the shared account or when Okta Privileged Access has the Okta-managed access setting enabled. Enable the Organizational Unit in the Active Directory integration settings and disable the Okta-managed access setting to resolve the issue.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Privileged Access (OPA)
- Active Directory (AD)
Cause
There are two possible root causes for this issue:
- The Active Directory integration in the Okta tenant does not have the Organizational Unit (OU) for the shared account selected.
- Okta Privileged Access configuration has the Keep accounts for Okta-managed access setting enabled.
Solution
What are the correct Active Directory integration settings?
Enable the Organizational Unit for the shared account in the Active Directory integration settings within the Okta Admin Console.
- Go to Directory > Directory Integrations.
- Select the Active Directory instance.
- Go to the Provisioning tab and select Integration.
- Enable the OU for the shared account in the OUs connected to Okta section.
Configure the Active Directory account rules in Okta Privileged Access
Please review the Okta Documentation for full guidance on setting up Active Directory account rules in Okta Privileged Access.
How does the System Log verify the account discovery?
Synchronize the application users in Okta Privileged Access and verify the successful discovery of the Active Directory accounts in the System Log.
- Run an Active Directory Synchronize app users task in Okta Privileged Access (Ref 1 in screenshot).
- Query the Okta System Log for
eventType eq "pam.active_directory.account_discovery.complete"to verify the "(PAM) Discovery of Active Directory accounts complete" event. - View the accounts in Okta Privileged Access.
