Okta Administrator Exam Part 1
With delegated authentication, users use? - answerAD credentials to sign in to Okta.
Enabled by default when integrating with AD instance
Enabling DSSO allows for? - answerUsers to be automatically authenticated by Okta,
and any apps connected to Okta whenever signing into windows network.
How does Okta make DSSO work? - answerOkta IWA Web App uses Microsoft IWA
and ASP.NET to authenticate users from specified gateways
Purpose of View Del Auth system log? - answerTo help identify auth bottlenecks ,
system includes information about duration of each delegated authentication request
- Located under Directory Integration under specified directory
When new attribute is added to AD domain? - answerEach Okta Agent needs to be
restarted.
- If not agents will base-64 the attributes
Member server is? - answerServer in AD domain or a Domain Controller
- Recommended for Okta to perform
3 Accounts required for AD Agent installtion? - answer- Local AD user account to run
agent installer
- Okta Super Admin, used to install AD agent
- OktaService account to run AD agent
OktaService account requisites? - answer- Member of domain admins group
- Have local admin privileges
AD Agent performs? - answer- Read users, OUs, and groups
- Authenticates users
- Change passwords
- CRUD, requires RW access
Minimum Okta Service Account Permissions - answer- Provision users
- Update user attrs
- Group Push
- Reset password
- Activate/Deactivate users
, By default Okta uses the Okta...? - answeruser profile username during delegated
authentication
User OUs connected to Okta - - answerAgent can only access OUs you select to import
end users
Group OUs connected to Okta - answerAgent can only access OUs you select to import
groups
Changing default filter query in your directory environment can? - answerDeprovision
users
JIT Provisioning - answerEnables automatic user account creation in Okta the first time
a user authenticates with AD Delegated Authentication, as well as updates to existing
user profiles.
- Imports security group which the user belongs to
To Enable Sync Password? - answerDelegated Authentication must be disabled
SSL Pinning Prevents? - answerCommunication with Okta Server
Use group rules to add users to AD - answerCreate Group that when added to the
group they are added to AD
Configuring Import and Account Settings - answer- Import settings to add users and
groups from designated AD domain into Okta.
- Includes which users and group OUs to import from
- Whether to use JIT provisioning
- How often to schedule imports
Instance-level Del Auth is optimized for ? - answerUse in environments with multiple AD
instances
Best Practice for Okta AD Agents? - answerInstall 2 or more Okta AD agents on
separate servers in each domain
Okta AD Agent Request handling - answer- Each agent connects to Okta
independently, if unavailable agent is removed from queue and is not given additional
tasks
AD Agent Availability - answer- Okta sends message to agent if no response for 120
seconds, marked as unavailable
- 30 days of inactivity, API token expires , causing you to reinstall
With delegated authentication, users use? - answerAD credentials to sign in to Okta.
Enabled by default when integrating with AD instance
Enabling DSSO allows for? - answerUsers to be automatically authenticated by Okta,
and any apps connected to Okta whenever signing into windows network.
How does Okta make DSSO work? - answerOkta IWA Web App uses Microsoft IWA
and ASP.NET to authenticate users from specified gateways
Purpose of View Del Auth system log? - answerTo help identify auth bottlenecks ,
system includes information about duration of each delegated authentication request
- Located under Directory Integration under specified directory
When new attribute is added to AD domain? - answerEach Okta Agent needs to be
restarted.
- If not agents will base-64 the attributes
Member server is? - answerServer in AD domain or a Domain Controller
- Recommended for Okta to perform
3 Accounts required for AD Agent installtion? - answer- Local AD user account to run
agent installer
- Okta Super Admin, used to install AD agent
- OktaService account to run AD agent
OktaService account requisites? - answer- Member of domain admins group
- Have local admin privileges
AD Agent performs? - answer- Read users, OUs, and groups
- Authenticates users
- Change passwords
- CRUD, requires RW access
Minimum Okta Service Account Permissions - answer- Provision users
- Update user attrs
- Group Push
- Reset password
- Activate/Deactivate users
, By default Okta uses the Okta...? - answeruser profile username during delegated
authentication
User OUs connected to Okta - - answerAgent can only access OUs you select to import
end users
Group OUs connected to Okta - answerAgent can only access OUs you select to import
groups
Changing default filter query in your directory environment can? - answerDeprovision
users
JIT Provisioning - answerEnables automatic user account creation in Okta the first time
a user authenticates with AD Delegated Authentication, as well as updates to existing
user profiles.
- Imports security group which the user belongs to
To Enable Sync Password? - answerDelegated Authentication must be disabled
SSL Pinning Prevents? - answerCommunication with Okta Server
Use group rules to add users to AD - answerCreate Group that when added to the
group they are added to AD
Configuring Import and Account Settings - answer- Import settings to add users and
groups from designated AD domain into Okta.
- Includes which users and group OUs to import from
- Whether to use JIT provisioning
- How often to schedule imports
Instance-level Del Auth is optimized for ? - answerUse in environments with multiple AD
instances
Best Practice for Okta AD Agents? - answerInstall 2 or more Okta AD agents on
separate servers in each domain
Okta AD Agent Request handling - answer- Each agent connects to Okta
independently, if unavailable agent is removed from queue and is not given additional
tasks
AD Agent Availability - answer- Okta sends message to agent if no response for 120
seconds, marked as unavailable
- 30 days of inactivity, API token expires , causing you to reinstall