NidhinC.60762 (Customer) asked a question.
0D50Z00008G7UuESAVOkta Classic EngineAdministrationAnswered2022-11-01T21:13:04.000Z2017-03-27T12:31:11.000Z2018-08-12T04:16:08.000Z
Okta in kiosk machine
Hi Experts, We have enabled SSO in our org and we have few Kiosk machines where we need to go to login page if someone opens okta page. How can we achieve this? Note: Kiost machiens are domain joined.
Mani (Customer)If you dont want to uncheck those Ous, then as a work around If there are few users in those Ou's put the users in the mode (No password. Click Reset Password to reset the user password.) You can achieve this mode when you disconnect the user from AD. So that user will never be able to login. If they ask for okta login , delete the user and ask the user to re register to okta. ( deactivate and then tombstone or Delete) This is just a work around.Expand Post
- cody.suders1.3982070751843718E12 (Okta, Inc.)What most customers do in this instance is use a group policy to make our interactive login page the home page on the shared machines. you can force interactive login instead of the desktop single sign-on experience by adding /login/default to the end of your URL ex: https://customer.okta.com/login/defaultExpand Post
- NidhinC.60762 (Customer)Hi Cody, if we apply this solution, whenever user opens browser from kios machine, the home page will open in okta login page right. So if a user needs to access Google page, they need to type google in url. this complicates right? Is there any other solution? We tried below methord and its working fine.
- Disable the sync for specific OU where we have this user account which is configured on Kiosk machine. So when user tries to access the okta page it will never login because user account does not exist in Okta org hence user will get redirected to Okta credentil page
Expand Post
Mani (Customer)If you dont want to uncheck those Ous, then as a work around If there are few users in those Ou's put the users in the mode (No password. Click Reset Password to reset the user password.) You can achieve this mode when you disconnect the user from AD. So that user will never be able to login. If they ask for okta login , delete the user and ask the user to re register to okta. ( deactivate and then tombstone or Delete) This is just a work around.Expand Post- NidhinC.60762 (Customer)Thanks Cody & Manlkanta for your suggestions. Other solution which we found is to relove the last name from the service account. In our environment we dont use last name for service accounts.Expand Post
This question is closed.
