## TL;DR
Wait 2 to 5 minutes and retry; Okta-to-AD password sync is not instant. If it still fails, confirm the reset actually completed in Okta Admin (check the user's password-changed timestamp) and have the user type the password manually instead of pasting it. Clear any saved credentials in the browser or credential manager.

## The error
```text
Sign-in failed: invalid credentials. Please check your username and password and try again.
```

## Steps
1. Ask the user to wait 3 minutes, then type the new password manually (no paste, no autofill). Expected: login succeeds. Pasting can smuggle trailing spaces; autofill can hold the old password.
2. If it still fails, check in Okta Admin: Directory > People > the user > Profile > password changed timestamp. Expected: the timestamp matches the reset. If it does not, the reset never committed; run the reset again.
3. For AD-mastered users, check Okta AD agent sync status (Settings > Integrations > AD). Expected: last sync within the last few minutes. A stalled agent delays writeback.
4. On the user's machine, open Credential Manager (Windows) or Keychain (macOS) and delete saved Okta credentials. Expected: next login prompts fresh and accepts the new password.
5. Verify the new password meets the AD password policy (length, complexity, history). Expected: policy check passes. A reset that violates AD policy can appear to succeed in Okta but fail at AD.

## When to use
- Password reset completed but sign-in still rejects the password
- Works in Okta but fails on AD-joined resources (or vice versa)

## When not to use
- Account is locked (check lockout status first)
- MFA is the failing step, not the password
- The user cannot complete the reset flow at all

## Compatibility
- Okta with Active Directory delegated authentication or password sync
- Okta Identity Engine and Classic

## Variants
### Password works for Okta but not for VPN
The VPN may cache the old password or use a different auth source. Reconnect the VPN client and re-enter credentials.
### "Password expired" immediately after reset
The AD "user must change password at next logon" flag may be set. Clear it in AD Users and Computers.

## Why it happens
Okta and AD are two systems joined by a sync agent. The reset lands in Okta first and propagates to AD on a schedule. Anything in that path (stalled agent, policy mismatch, cached credentials) produces the illusion that the new password is wrong.

## Edge cases
- Users with passwords containing non-ASCII characters: some AD clients mangle them; stick to ASCII.
- Federated users whose password lives in a third IdP: reset must happen there, not in Okta.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_gtieLf95KvMTmULQtBrKSg
