<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008C3jcuSABOkta Classic EngineAdministrationAnswered2024-03-25T23:03:00.000Z2016-05-20T20:25:47.000Z2020-09-02T11:57:58.000Z
s9is5 likes this.
  • Hey Tien - Since responding to this question, I've gained more context and I think I should elaborate on my response: Okta supports the passive federation flow for SAML authentication by default, which describes the SP-initiated SAML SSO flow. I've since learned that you're asking if Okta currently respects the isPassive flag in the SAML Assertion metadata. The desired behavior is that the IDP (Okta) to redirect back to the SP without prompting the end user for credentials, if a session is not currently established. The end user would then log in directly to the application on the SP side. Okta does nto currently honor this flag. Sorry for the confusion.

    Expand Post
  • Tien-OktaSSO (BMC Software)

    More and more SaaS vendor supports Passive Authentication flow (with isPassive flag in AuthRequest) as out of the box feature. It improves end-user experience a lots because it recognizes the Okta session when user travel to Okta integrated applications without requiring the user to click on Login to initiate authentication request. I submitted enhancement requested here: https://support.okta.com/help/ideas/ideaList.apexp?c=09aF0000000Tj5M&lsi=1&lsr=10&u=005F0000005DwFL Thanks for the follow-up.
    Expand Post
  • s9is5 (s9is5)

    Hi, do you have any news on this? The idea now has 130 votes and is indeed something that our organization needs as well. Can you tell us if development is considering this request? 

    Also, by the way, ideas are very hard to find in this community. there is no navigation to them and the ideas don't show up in search results either.
  • Tien-OktaSSO (BMC Software)

    Hi Eirc, do we this feature scheduled on Okta short term roadmap?
  • 7nfgz (7nfgz)

    Also really interested in an update on this. It has been ages!

This question is closed.
Loading
Does Okta support Passive authentication as a IDP?