> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/operations/setting-up-password-management.md).

# Setting up password management

Configure the management agent to set and change Okta user passwords.

The management agent supports both MIM password operations:

* **Set password**, where MIM supplies only the new password. This is what password reset and password synchronization use.
* **Change password**, where MIM supplies the current password as well. Okta validates the current password before applying the new one.

Either way the password goes to Okta, and Okta's password policy decides whether it is accepted.

## Step 1: Get user synchronization working first

Configure and test user imports before you enable password management. A password operation targets a joined connector, so if the joins are wrong the passwords go to the wrong place or nowhere at all.

Confirm the source and Okta connectors are joined through the intended metaverse object.

## Step 2: Configure Okta access

With OAuth, grant `okta.users.manage` to the service app, and assign an admin role that includes the credential permissions listed in [Creating the OAuth service app](/okta-ma/authentication/creating-the-oauth-service-app.md#step-5-assign-an-admin-role). Make sure the target users fall inside the app's resource set.

With an API token, the account that created it needs the same access.

Okta will also refuse a password that the user's password policy rejects, and some operations depend on the user's status and authentication provider. A user mastered by an external provider, for example, won't accept a password from MIM.

## Step 3: Configure MIM password synchronization

This is ordinary MIM password management, with the Okta management agent as a target:

1. Configure the password-management infrastructure for the source system. For Active Directory, that means PCNS on the relevant domain controllers.
2. Enable password synchronization in MIM and select the source and Okta management agents.

MIM password synchronization is one-way, so pick a single authoritative source. Microsoft's [password management documentation](https://learn.microsoft.com/en-us/microsoft-identity-manager/infrastructure/mim2016-password-management) covers the MIM and PCNS side.

## Passwords on newly created users

A user created by an export is created against the Okta authentication provider with no password, unless MIM supplies one as part of the create. If it does, the connector includes it in the create request, so the user exists with that password from the moment it is created rather than getting one on a later operation.

## Step 4: Test

1. Pick a non-production user that is joined to the right Okta connector.
2. Run the set or change operation you need and confirm MIM reports success.
3. Sign in to Okta as that user to confirm the password works.
4. Test a password you know the Okta policy will reject, and confirm the failure is visible to whoever operates the system.

Don't skip the last test. A password rejected by the Okta policy is the most common failure you'll see in production, and it's worth knowing what it looks like in MIM before it happens with a real user.

If a password is rejected, check the Okta password policy, the user's status and authentication provider, the service app or token permissions, and, for a change operation, the current password MIM supplied.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/operations/setting-up-password-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
