<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR0000204aom0AAOkta Classic EngineIntegrationsAnswered2026-08-13T15:38:51.000Z2026-08-13T04:46:35.000Z2026-08-13T15:38:51.000Z

KeiK.29963 (Customer) asked a question.

Network Requirements for Okta AD Agent

For directory integration with Active Directory, we are planning to build a new Windows Server on an AWS EC2 instance, separate from our existing AD servers, and install the Okta AD Agent on it.

Could you please provide specific details regarding the network requirements necessary for the Okta AD Agent to communicate with Okta, particularly from the following perspectives?

  • The IP addresses / URLs / FQDNs required for outbound communication, along with the ports and protocols used
  • If applicable, the IP addresses / URLs / FQDNs required for inbound communication, along with the ports and protocols used
  • For the above communications, whether allowlisting by IP address or by FQDN is recommended
  • How to identify or reference the applicable Okta cell / IP ranges
  • The IP addresses / destinations / ports / protocols required for communication from the Okta AD Agent to the AD domain controllers

In addition, we understand that the following items are primarily related to AWS-side configuration, but we would appreciate it if you could share any relevant knowledge or guidance you may have:

  • AWS requirements related to Security Groups, NACLs, Route Tables, NAT Gateway, Proxy, and DNS

 

Thank you for your support.


  • Paul S. (Okta, Inc.)

    Hello @KeiK.29963 (Customer)​ Thank you for posting on our Community page!

     

    The Okta AD Agent requires outbound HTTPS communication to Okta and inbound LDAP/LDAPS communication from domain controllers. Domain allowlisting is recommended over IP ranges for flexibility, and your Okta cell must be identified to determine the correct IP ranges. AWS configuration requires Security Groups, network routing, and DNS resolution to support this architecture.

    You can determine your Okta cell by navigating to your Okta Admin Console and checking the organization information page, which displays your cell assignment (for example, "OK11 Cell (US)"). The cell name maps to entries in the Okta IP ranges list.

    For IP ranges and domains for allowlisting you can review our documentation below:

    https://okta-help.pixtulate.com/en-us/content/topics/security/ip-address-allow-listing.htm

     

    Also for additional AD agent prerequisites you can review our full documentation below:

    https://okta-help.pixtulate.com/oie/en-us/content/topics/directory/ad-agent-prerequisites.htm

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post

Loading
Network Requirements for Okta AD Agent