Office 365 Federated Domain Users Must Authenticate With Okta
Last Updated:
Overview
When an organization federates a domain in the Office 365 integration, Office 365 redirects all users within that federated domain (for example, <user@domain.com>) to Okta for authentication. Microsoft federation does not allow excluding specific users from the Okta authentication step. All users within the federated domain must have a Microsoft account, an Okta account, and an assignment to the Office 365 application in Okta to access Microsoft-related resources.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Office 365
- Single Sign-On (SSO)
Solution
Can specific users be excluded from Okta authentication in a federated Office 365 domain?
Microsoft federation operates at the domain level and does not allow excluding specific users from Okta authentication. When testing Office 365 federation, use a dummy domain or a domain without active users to avoid disrupting access. If active users experience issues and require direct authentication with Microsoft, remove the domain federation completely by following the steps in the Remove Microsoft Office 365 Federation Using the Okta Admin Console documentation.
