Trusted Domain Skip to main content
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Mark RileyMark Riley 

Trusted Domain

We have 2 AD Domains, Domain A and Domain B. Both domains have Okta SSO configured, so a user from Domain A logging into a computer from Domain A will automaticaly SSo into Okta and apps such as O365 will authenticate using SSo. The same applies for a user from Domain B logging into a computer from Domain B

When a user from Domain B logs into a computer from Domain A, SSo does not work. Can you provide assistance with the configuration require for this use case? Thanks
Andrei AldeaAndrei Aldea (Okta, Inc.)

Hello Mark,

The use case you described, having a user from Domain B logging on a machine that belongs to Domain A would not work for IWA authentication due to the fact that the user does not exist on the same domain as the machine.

Even if there is a two-way trust between domains, I don't believe this would be possible.

Thank you,
Andrei Aldea
Technical Support Engineer
Okta Global Customer Care

Kris DarbyshireKris Darbyshire
Hi Mark,

You can always use UPN transformation to rewrite the UPN suffix of users from different domains. I know okta support is pretty garbage, but I would at least expect them to tell you this instead of saying "I don't believe this would be possible". 

Anyway try UPS transform in the web.conf file on your IWA server.

Best of luck!

Dylann FezeuDylann Fezeu (Customer First Programs)

Thanks for posting your inquiry in Okta Community Portal.

​If you receive a great answer to your question(s), please help readers find it by marking it the best answer. Hover over the answer and click "Best Answer." 

Thank you,

​Dylann Fezeu
Okta Help Center Team