OKTA ADMINISTRATOR EXAM
QUESTIONS AND CORRECT ANSWERS.
With delegated authentication, users use?
AD credentials to sign in to Okta. Enabled by default when integrating with AD instance
Enabling DSSO allows for?
Users to be automatically authenticated by Okta, and any apps connected to Okta whenever
signing into windows network.
How does Okta make DSSO work?
Okta IWA Web App uses Microsoft IWA and ASP.NET to authenticate users from specified
gateways
Purpose of View Del Auth system log?
To help identify auth bottlenecks , system includes information about duration of each delegated
authentication request
- Located under Directory Integration under specified directory
When new attribute is added to AD domain?
Each Okta Agent needs to be restarted.
- If not agents will base-64 the attributes
Member server is?
Server in AD domain or a Domain Controller
- Recommended for Okta to perform
3 Accounts required for AD Agent installtion?
,- Local AD user account to run agent installer
- Okta Super Admin, used to install AD agent
- OktaService account to run AD agent
OktaService account requisites?
- Member of domain admins group
- Have local admin privileges
AD Agent performs?
- Read users, OUs, and groups
- Authenticates users
- Change passwords
- CRUD, requires RW access
Minimum Okta Service Account Permissions
- Provision users
- Update user attrs
- Group Push
- Reset password
- Activate/Deactivate users
By default Okta uses the Okta...?
user profile username during delegated authentication
User OUs connected to Okta -
Agent can only access OUs you select to import end users
Group OUs connected to Okta
Agent can only access OUs you select to import groups
Changing default filter query in your directory environment can?
Deprovision users
, JIT Provisioning
Enables automatic user account creation in Okta the first time a user authenticates with AD
Delegated Authentication, as well as updates to existing user profiles.
- Imports security group which the user belongs to
To Enable Sync Password?
Delegated Authentication must be disabled
SSL Pinning Prevents?
Communication with Okta Server
Use group rules to add users to AD
Create Group that when added to the group they are added to AD
Configuring Import and Account Settings
- Import settings to add users and groups from designated AD domain into Okta.
- Includes which users and group OUs to import from
- Whether to use JIT provisioning
- How often to schedule imports
Instance-level Del Auth is optimized for ?
Use in environments with multiple AD instances
Best Practice for Okta AD Agents?
Install 2 or more Okta AD agents on separate servers in each domain
Okta AD Agent Request handling
- Each agent connects to Okta independently, if unavailable agent is removed from queue and is
not given additional tasks
AD Agent Availability
QUESTIONS AND CORRECT ANSWERS.
With delegated authentication, users use?
AD credentials to sign in to Okta. Enabled by default when integrating with AD instance
Enabling DSSO allows for?
Users to be automatically authenticated by Okta, and any apps connected to Okta whenever
signing into windows network.
How does Okta make DSSO work?
Okta IWA Web App uses Microsoft IWA and ASP.NET to authenticate users from specified
gateways
Purpose of View Del Auth system log?
To help identify auth bottlenecks , system includes information about duration of each delegated
authentication request
- Located under Directory Integration under specified directory
When new attribute is added to AD domain?
Each Okta Agent needs to be restarted.
- If not agents will base-64 the attributes
Member server is?
Server in AD domain or a Domain Controller
- Recommended for Okta to perform
3 Accounts required for AD Agent installtion?
,- Local AD user account to run agent installer
- Okta Super Admin, used to install AD agent
- OktaService account to run AD agent
OktaService account requisites?
- Member of domain admins group
- Have local admin privileges
AD Agent performs?
- Read users, OUs, and groups
- Authenticates users
- Change passwords
- CRUD, requires RW access
Minimum Okta Service Account Permissions
- Provision users
- Update user attrs
- Group Push
- Reset password
- Activate/Deactivate users
By default Okta uses the Okta...?
user profile username during delegated authentication
User OUs connected to Okta -
Agent can only access OUs you select to import end users
Group OUs connected to Okta
Agent can only access OUs you select to import groups
Changing default filter query in your directory environment can?
Deprovision users
, JIT Provisioning
Enables automatic user account creation in Okta the first time a user authenticates with AD
Delegated Authentication, as well as updates to existing user profiles.
- Imports security group which the user belongs to
To Enable Sync Password?
Delegated Authentication must be disabled
SSL Pinning Prevents?
Communication with Okta Server
Use group rules to add users to AD
Create Group that when added to the group they are added to AD
Configuring Import and Account Settings
- Import settings to add users and groups from designated AD domain into Okta.
- Includes which users and group OUs to import from
- Whether to use JIT provisioning
- How often to schedule imports
Instance-level Del Auth is optimized for ?
Use in environments with multiple AD instances
Best Practice for Okta AD Agents?
Install 2 or more Okta AD agents on separate servers in each domain
Okta AD Agent Request handling
- Each agent connects to Okta independently, if unavailable agent is removed from queue and is
not given additional tasks
AD Agent Availability