Mark Riley 

Trusted Domain

We have 2 AD Domains, Domain A and Domain B. Both domains have Okta SSO configured, so a user from Domain A logging into a computer from Domain A will automaticaly SSo into Okta and apps such as O365 will authenticate using SSo. The same applies for a user from Domain B logging into a computer from Domain B

When a user from Domain B logs into a computer from Domain A, SSo does not work. Can you provide assistance with the configuration require for this use case? Thanks
Andrei Aldea

Hello Mark,

The use case you described, having a user from Domain B logging on a machine that belongs to Domain A would not work for IWA authentication due to the fact that the user does not exist on the same domain as the machine.

Even if there is a two-way trust between domains, I don't believe this would be possible.

Kris Darbyshire
Hi Mark,

You can always use UPN transformation to rewrite the UPN suffix of users from different domains. I know okta support is pretty garbage, but I would at least expect them to tell you this instead of saying "I don't believe this would be possible". 

Anyway try UPS transform in the web.conf file on your IWA server.

Best of luck!

Dylann Fezeu

