<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7UuESAVOkta Classic EngineAdministrationAnswered2022-11-01T21:13:04.000Z2017-03-27T12:31:11.000Z2018-08-12T04:16:08.000Z
  • Mani (Customer)

    If you dont want to uncheck those Ous, then as a work around If there are few users in those Ou's put the users in the mode (No password. Click Reset Password to reset the user password.) You can achieve this mode when you disconnect the user from AD. So that user will never be able to login. If they ask for okta login , delete the user and ask the user to re register to okta. ( deactivate and then tombstone or Delete)  This is just a work around.

     

    Expand Post
    Selected as Best
  • What most customers do in this instance is use a group policy to make our interactive login page the home page on the shared machines.  you can force interactive login instead of the desktop single sign-on experience by adding /login/default to the end of your URL ex: https://customer.okta.com/login/default
  • NidhinC.60762 (Customer)

    Hi Cody, if we apply this solution, whenever user opens browser from kios machine, the home page will open in okta login page right. So if a user needs to access Google page, they need to type google in url. this complicates right?

     

    Is there any other solution? We tried below methord and its working fine. 
    • Disable the sync for specific OU where we have this user account which is configured on Kiosk machine. So when user tries to access the okta page it will never login because user account does not exist in Okta org hence user will get redirected to Okta credentil page
     

    Problem with the above methord is that, if some user from non synced OU asks for an Okta login then we will have to move that user from the non synced OU to synced OU. 

     

    So is there any way using group or something we can restrict Okta access so that they will get redirected to Okta login page
    Expand Post
  • Mani (Customer)

    If you dont want to uncheck those Ous, then as a work around If there are few users in those Ou's put the users in the mode (No password. Click Reset Password to reset the user password.) You can achieve this mode when you disconnect the user from AD. So that user will never be able to login. If they ask for okta login , delete the user and ask the user to re register to okta. ( deactivate and then tombstone or Delete)  This is just a work around.

     

    Expand Post
    Selected as Best
  • NidhinC.60762 (Customer)

    Thanks Cody & Manlkanta for your suggestions. 

     

    Other solution which we found is to relove the last name from the service account. In our environment we dont use last name for service accounts.
This question is closed.
Loading
Okta in kiosk machine