Configure Duo Security as an OpenID Connect Identity Provider in Okta
Last Updated:
Overview
Configuring Duo Security as an OpenID Connect (OIDC) Identity Provider (IdP) in Okta requires Okta Support to enable specific feature flags. Once enabled, the OpenID Connect IdP option becomes available in the Okta Admin Console, allowing the integration to proceed.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Duo Security
- OpenID Connect (OIDC) Identity Provider (IdP)
Solution
How is Duo Security configured as an OpenID Connect Identity Provider?
Request the required feature flags from Okta Support, verify the enablement in the Okta Admin Console, and configure the integration.
- Contact Okta Support and request the enablement of the following features on the Okta tenant:
TOP_WINDOW_REAUTH_FROM_ENDUSER_SETTINGSSTATE_TOKEN_ALL_FLOWSCLAIMS_AS_FACTORGENERIC_OIDC_IDP
- Verify the feature enablement by navigating to the Okta Admin Console and checking for the OpenID Connect IdP option under Identity Providers.
- Configure the OIDC IdP by following the Okta documentation for generic OIDC identity providers.
NOTE: If the Factors API is not retrieving the Duo IdP factor, contact Okta Support and verify that all four features listed above are enabled on the tenant.
What are the additional considerations for Duo Federal?
When setting up Duo Federal OIDC Universal Prompt and requiring the "(Beta) Asymmetric Signing for WebSDK 4" feature flag, contact Duo Support directly to request enablement.
