<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7UyCSAVOkta Classic EngineLifecycle ManagementAnswered2024-04-15T10:07:27.000Z2017-12-12T15:42:23.000Z2018-07-31T17:29:41.000Z
Whitelisting assertions from Okta
Are the IP addresses contained in this link the same I would whitelist in an application in order to receive SAML assertions being sent from Okta? The article talks more of outbound calls to Okta rather than calls from Okta to service providers.  https://support.okta.com/help/Documentation/Knowledge_Article/Configuring-Firewall-Whitelisting-89944588

 


  • Hi Keith,

     

    The article you included provides a list of IPs that need to be whitelisted if your server policy does not allow outbound communications to any IPs/sites. Whilelisting them ensures that your users will not encounter any issues reaching your Okta org.

     

    When a user accesses an application from the Okta side (or via SP-initiated login flow if that's supported by the app), their request will contain both the local user's IP as well as one of the IPs in the same list you provided.

     

    So for both inbound and outbound traffic, the IP list for Okta should be the same.

     

    Regards,

    Andrei Aldea

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
  • CloudI.67773 (Customer)

    Andrel,

     

    Thank you for the response. Does this include the API calls made by Okta when trying to do provisioning to a Service Provider?

  • zkaxt (zkaxt)

    Any update on if the IP addresses are the same that the provisioning will use to make calls to SP?
  • CloudI.67773 (Customer)

    Dave,

     

    After testing, the IP range is most likely the entire AWS region your Okta Cell lies in. They never matched the list provided.
This question is closed.
Loading
Whitelisting assertions from Okta