Update Okta Office 365 Single Sign-On Applications to Support the SHA-256 Algorithm
Last Updated:
Overview
Okta upgraded the Office 365 Single Sign-On (SSO) integration to use the SHA-256 algorithm for signing authentication tokens. To utilize this upgraded integration, administrators must migrate the Office 365 application in Okta. This change aligns with recommendations for robust cryptographic practices and supports the gradual deprecation of older algorithms. By employing a 256-bit hash, SHA-256 significantly reduces the risk of collision and preimage attacks compared to SHA-128, thereby enhancing overall system security.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Office 365 application with Single Sign-On (SSO) enabled
- Office 365 SSO applications migrated to Microsoft Graph
- SHA-256 algorithm
Solution
What are the prerequisites for migrating Office 365 Single Sign-On applications?
Verify that the following prerequisites are met to ensure the Office 365 Single Sign-On applications are ready for migration.
- An Office 365 application with Single Sign-On enabled exists.
- An App Administrator role in Okta is available to migrate the Office 365 Single Sign-On applications.
- The Office 365 Single Sign-On applications are migrated to Microsoft Graph. If not, complete the migration using either the Single Sign-On with WS-Fed Automatic or Single Sign-On with WS-Fed Manual with PowerShell configuration methods.
How are applications with WS-Fed Automatic configuration updated?
Update the WS-Fed Automatic configuration by navigating to the application sign-on settings and saving the configuration.
- In the Admin Console, go to Applications > Applications.
- Select the Office 365 application that has WS-Fed Automatic enabled.
- Select the Sign On tab.
- Select Edit, scroll to the bottom of the page, and select Save.
Applications with WS-Fed Manual configuration require PowerShell commands to update.
Update the WS-Fed Manual configuration by copying the provided PowerShell command from the setup instructions and running it before updating the application in Okta.
- In the Admin Console, go to Applications > Applications.
- Select the Office 365 application that has WS-Fed Manual with PowerShell configuration enabled.
- Select View Setup Instructions to open the instructions on a new page.
- On the instruction page, scroll to the If your domain is already federated, enter the following section and copy the command to run it in PowerShell.
- Once the PowerShell command completes, return to the Office 365 application Sign On tab and select Update Now.
- Select the confirmation checkbox and select Update Now.
Contact Okta support
For any issues related to migration, contact Okta support.
