2 ms·
Typically, when you build an authentication system, you design your code to not store the password in plaintext so that there is no possibility of the password
by jf 4y ago
Typically, when you build an authentication system, you design your code to not store the password in plaintext so that there is no possibility of the password being read back out of the system, but Okta isn't doing this because they need to be able to do password syncing.
Incorrect. Okta stores passwords as hashes.
By default, random passwords are synchronized when an administrator sets up SCIM and enables password synchronization. If the administrator specifically configures SCIM to synchronize the real passwords, then the downstream system will only get the real password for a user after a user successfully logs in.