<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta IWA Desktop Single Sign-On Fails on a Windows Computer

Administration
Okta Classic Engine
Directories
Okta Identity Engine

Overview

When web browsers lack the proper configuration for Desktop Single Sign-On (DSSO), authentication fails and redirects to the Okta login page. Resolving this requires adding the Integrated Windows Authentication (IWA) server URL and the Okta org URL to the Local intranet zone in Windows Internet Options.

Applies To

  • Okta Classic Engine
  • Desktop Single Sign-On (DSSO)
  • Integrated Windows Authentication (IWA)

Cause

The web browsers lack the required configuration for Desktop Single Sign-On.

Solution

How is the Desktop Single Sign-On failure due to browser configuration resolved on Windows computers?

 

Test IWA from the client machine by accessing https://<myIWA_server>/IWA/authenticated.aspx to ensure there is no prompt for Windows credentials.

If a prompt for Windows credentials appears, add the IWA server URL and the Okta org URL as Local Intranet Sites in the Windows Network and Internet settings.

  1. On the Windows Control Panel, select Network and Internet > Internet Options > Security > Local intranet > Sites > Advanced.
  2. In the Add this website to the zone field, enter the appropriate URLs.
  3. Select Add.
  4. Select OK twice to close the Internet Options window.

The following image displays the Local intranet zone configuration screen in Windows Internet Options.

Internet Options configuration screen

 

 

Related References

Loading
Okta Support - Okta IWA Desktop Single Sign-On Fails on a Windows Computer