This article addresses an error that occurs when a user selects Sign In with Okta for the managed Slack application on an Android device with a Work Profile.
The following error message is displayed:
We're unable to open this link.
- Slack with Security Assertion Markup Language
- Android mobile devices
- Android For Work
- Okta Classic Engine
By default, Android For Work (AFW) applications cannot access the device's native applications. In this scenario, Slack attempts to launch Chrome to handle the Okta authentication, but the Work Profile cannot launch the native Chrome application located in the Personal Profile.
Perform one of the two following solutions.
Solution 1: Deploy the Chrome application to the AFW Profile
-
In the Okta Admin Console, navigate to Applications > Applications.
-
Click Add Application.
-
In the search bar, enter
Chrome Browserand click Add. -
On the General Settings screen, select the Do not display application icon to users and Do not display application icon in the Okta Mobile app options.
-
Assign the application to all users or groups that enroll devices into AFW, click Next, and then click Done.
-
On the application page for Chrome Browser, select the Mobile tab.
-
Click the pencil icon next to Chrome Browser Android (Universal).
-
Select the Silently install this app and Make this app available to users in the Okta Mobile App Store options.
-
From the Runtime permissions drop-down menu, select Approve All.
-
Click Save.
On AFW-enrolled devices, the Chrome application is automatically added to the Work Profile and accessed by Slack during sign-in attempts.
Solution 2: Allow AFW to open the existing Chrome application from the Personal Profile
NOTE: This option allows applications in the device's Personal Profile to access AFW data. For example, attachments in work emails can be downloaded to the device's internal storage and then forwarded using a personal email account.
-
In the Okta Admin Console, navigate to Devices > Mobile Policies.
-
Locate the Device Policy assigned to the affected users.
-
Click the pencil icon next to the Android platform.
-
Click Next.
-
Select the Work profile can transfer data to personal profile checkbox and click Save.
