Okta is committed to delivering the highest level of security for its customers. To reinforce this commitment, Okta is upgrading its Office 365 Single Sign-on integration to use the SHA-256 algorithm for signing authentication tokens. This change aligns with NIST’s recommendations for robust cryptographic practices and supports the gradual deprecation of older, less secure algorithms. By employing a 256-bit hash, SHA-256 significantly reduces the risk of collision and preimage attacks compared to SHA-128, thereby enhancing overall system security.
To take advantage of this upgraded integration, customers using Office 365’s Single Sign-on must follow the required actions below to migrate their Office 365 App in Okta.
- Office 365 application with Single Sign-on (SSO) enabled
- Office 365 SSO applications migrated to Microsoft Graph
- SHA-256 algorithm
Prerequisites
- There is an Office 365 application with Single Sign-on enabled.
- There is an App Administrator role in Okta to migrate the Office 365 Single Sign-on applications.
- The Office 365 Single Sign-On applications were migrated to Microsoft Graph. If not, please follow the steps below:
For WSFed Automatic Configuration
- In the Admin Console, go to Applications > Applications.
- Select the Office 365 application, which has WS-Fed Automatic enabled.
- Click the Sign-on tab.
- Click on Edit, scroll down to the bottom, and click Save.
For WSFed Manual with PowerShell Configuration
- In the Admin Console, go to Applications > Applications.
- Select the Office 365 application, which has WSFed Manual with PowerShell configuration enabled.
- Click on the View Setup Instructions, and a new page will open with instructions.
- On that instruction page, scroll down to the If your domain is already federated, enter the following section and copy the command to run it in PowerShell.
- Once it is completed, return to the Office 365 application’s Sign On tab and click the Update Now button.
- Check the box and click the Update Now button.
Contact Okta support
For any issues related to migration, contact Okta support.
