Skip to main content

Migrate passwords from on-prem AD to Okta

If you want to switch an AD-mastered Okta integration to Okta-mastered (that is, stop using AD delegated authentication and have Okta handle user logins instead), you need to move users’ passwords from AD into Okta.

Old ways of doing this were painful:

  • Forcing everyone to reset their password (disruptive and obvious to users), or

  • Building complex custom Org2Org hooks (heavy IT effort).​

As an early access feature, Okta now offers a better option on the AD instance’s Provisioning tab: a one-time, secure, phased password migration that’s invisible to users.

How it works:

  • While migration is enabled, users keep signing in as normal.

  • Each time AD successfully authenticates a user, their password is securely captured and copied to Okta.

  • From that point on, Okta authenticates that user directly.

  • Over time, all active users’ passwords move to Okta, and you can turn off delegated authentication.

End result: Okta becomes the central, cloud-based source of authentication instead of AD.


Did this answer your question?