We have integrated On-premise and Cloud SaaS applications in SSO. Major challenge we face in enforcing OKTA SSO is access for External users/contractors.We have many external conntractor/user working for us and they are not in the domain. How to include access for external users(not in domain)? OKTA mastered user is one of the option but managing ~120 users in OKTA is not looking a good option.

What other alternatives can we consider?

Hello Parth, The key question is where those users idenity exist today...
You can manage them in several ways.  If those identities reside in your contractors' AD or LDAP, you can connect directly to them with Okta's agent.  If they aren't in an AD or LDAP, as you mentioned, you can add them directly to Okta.
Hello Raja,

Thanks for the update. We have 2 user cases for different applications :

1) They are all different contractors in different company (4-5 contractors / company)
2) One external verndor has >30 contractors i think. Can you please suggest how we can identify them if they are in AD domain of a different company.