jszesq (Customer) asked a question.
0D50Z00008C3jn3SABOkta Classic EngineAdministrationAnswered2018-09-05T01:29:09.000Z2015-10-16T15:40:19.000Z2016-06-02T14:19:36.000Z
What are best practices where Okta MFA SSO interfaces with salesforce or Google IdP and Ad?
A bit more background...seeking a best practices approach for iOS, Android, Win and OS X Desktops etc. Network Topology:Abizinabox.com External 75.110.232.105 to .110192.168.50/27, 192.168.51/27, 192.168.22/27PDC DC-01 .55 Windows Server 2008R2BDC APP-02 .57 Windows Server 2008R2APPS 199.229.252.241 – OS X 10.10 – Open Directory Server Okta Enterprise Multi-Factor SSO Okta Universal Directory as ultimate IdPGoogle Authenticator, SMS and Back-up PasswordsSAML Enabled Wherever availableOkta Active Directory Agent and LDAP Agents tied into office network Google For Work Two Factor AuthenticationGoogle Authenticator, SMS, Application PasswordsGoogle MDM for iOS and ChromeGoogle SAML set up as IdP with AWS IAM for control Salesforce.com Salesforce Set Up as IDPSAML SSO
- edward.holliday1.413788283869593E12 (Okta, Inc.)Jordan, A lot of customers use the AD and LDAP Agents and Okta MFA to create an "Okta Sign On Policy" that enforces the use of MFA when employees are 'Off-network', for example when they are working at home.This type of MFA use case can also be useful as a way of retiring a VPN solution, which you may have protecting external employee access to certain protected applications. You know you will be able to replace the VPN with Okta MFA if you have configured a SAML only partnership with the SAML capable application and Okta. In your case this can be done with Salesforce and Google in SAML mode. Here is where you find this Security > Authentication > Multifactor
Some other customers still, will combine access to apps in Okta with integration (in order to invoke a VPN session) to their existing VPN using the Okta Radius Agent. If you have a lot of mobile access to apps and you have an Okta mobile product you might also be defing an 'Okta Mobile' native app policy under Security > Policies > Mobile
Edward Holliday, Principal Technical Consultant, Okta
Expand Post
This question is closed.
