<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Users Accessing Office 365 from Blocked Dynamic Network Zones
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

Users in blocked countries can still access Office 365 applications through Okta. The issue is isolated to Office 365 SP-initiated flow when using legacy endpoints Username13.

 

For example, for endpoint : app/office365/exkh2h9a8zSrnu8Io697/sso/wsfed/username13.

 

Users without a global session trying to access the Okta will be denied by the dynamic network zone.

Applies To
  • Office 365 
  • Legacy endpoint
  • Network zone
Cause

Users authenticating to O365 on specific endpoints are ignoring the global session policy.
The direct authentication endpoint does not create Okta sessions, so those policies are not enforced. Global Session Policies are not evaluated for the username13 endpoint. Only the Application Authentication Policies are evaluated.

Solution

As global session policies are not evaluated for this endpoint, update the application authentication policy by allowing or denying access based on the network zone.

Global session policies   

 

Related References

Loading
Users Accessing Office 365 from Blocked Dynamic Network Zones