When accessing Access Requests via a tile on the End User Dashboard, users are getting prompted again to login/authenticate, even though the Sign On policy for the application is not set to re-prompt/re-authenticate users.
This occurs when the user accesses the End User Dashboard via a Custom Domain (for example, login.company.com) and does not occur when accessing the End User Dashboard via the Okta Default Domain (for example, company.okta.com).
- Okta Identity Governance
- Access Requests
- Custom Domain
This occurs as the user has authenticated through a Custom Domain (for example, login.company.com) and Access Requests is authenticating against a session from the Okta Default Domain (for example, company.okta.com).
There are 2 Solutions available:
- Users will have to re-authenticate when accessing the Access Requests tile from the End User Dashboard when logging in through a Custom Domain (for example, login.company.com).
- Alternatively, to not re-authenticate, users can access the End User Dashboard by logging into the Okta Default Domain (for example, company.okta.com) instead.
- To have the user login via the Custom Domain and login/access the Access Request web app without getting prompted to log in to the Default Domain, a case can be opened with support to enable Access Request to authenticate through the Custom Domain instead of the Default Domain. Please see notes on functionality and items to include in the case submission to support:
- Include the following details if submitting the enablement request to Support:
- Okta Default Domain
- Okta OrgId
- Custom Domain URL (that will be authenticated against)
- NOTE
- After the Custom Domain is enabled, access to the Access Request app requires the user to be authenticated against the Custom Domain. If authenticated through the Okta Default Domain, the user will be prompted to re-login.
- Only 1 Custom Domain is supported.
- Include the following details if submitting the enablement request to Support:
