Remove Microsoft Office 365 Federation Using the Okta Admin Console
Last Updated:
Overview
The federation between Okta and Microsoft Office 365 can be removed by switching the sign-on type from WS-Federation (WS-Fed) to Secure Web Authentication (SWA) for the application or by deleting the application instance within the Okta Admin Console.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365 (O365) Federation
- Single Sign-On (SSO)
Solution
What are the steps to remove Microsoft Office 365 federation in the Okta Admin Console?
Review the following video to learn how to remove Microsoft Office 365 federation in the Okta Admin Console.
Remove the federation between Okta and Microsoft Office 365 by switching the sign-on type from WS-Federation (WS-Fed) to Secure Web Authentication (SWA) for the application or deleting the app instance.
NOTE: Okta does not recommend deleting the application. For manual federation, removing the application does not automatically de-federate the domain. Manual de-federation using PowerShell is required. However, with automatic federation, if the app is removed, the domain is de-federated automatically.
-
From the Okta Admin Console, navigate to Applications > Applications.
-
Locate the Microsoft Office 365 application that should be de-federated.
-
Go to the Sign On tab of the application.
-
Click on the Edit button.
-
Select Secure Web Authentication as the Sign On Type.
NOTE: Upon selecting Secure Web Authentication, a prompt appears to choose how the username and password are created. This setting determines the credentials used to log into Microsoft Office 365. Since WS-Federation does not use a password, the Microsoft Office 365 accounts might lack a valid password. Avoid this by enabling Sync Okta Password in the Provisioning settings of the Microsoft Office 365 application to push the Okta password to Microsoft Office 365.
-
Save the configuration.
What are the steps to remove specific federated domains from Microsoft Office 365?
Remove specific federated domains from Microsoft Office 365 by managing the verified domains in the application sign-on settings.
-
From the Okta Admin Console, navigate to Applications > Applications.
-
Locate the Microsoft Office 365 application that should be de-federated.
-
Go to the Sign On tab of the application.
-
Click on the Edit button.
-
Click on Manage verified domains to view the list of domains federated with Okta.
- Remove the domains that should be defederated and click Next.
-
Click Save.
De-federation takes time to complete, depending on Microsoft's processing time.
