<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VS6SANOkta Classic EngineIntegrationsAnswered2021-09-02T16:48:18.000Z2018-04-08T15:36:12.000Z2018-08-12T04:17:06.000Z
Social IdP's with Provisioning Callout
Hello everyone, 

 

We have been able to use Microsoft and Google as social Identity Providers but we now want to provision user accounts ourselves instead of automatic provisioning by the IDP. So, we have changed the "Provisioning Policy" to be "Callout" and after success authentication at Google/MS, Okta redirects the user to a custom page we maintain where we provision the user in Okta. But after this point ,how can we continue the original OpenID flow? We can't figure this out. Maybe there isn't a way.

 

As a workaround we are redirecting the user to the original Authorize URL for the second time but this results in a not great user experience for first time logins. Is there a better way to continue the original OpenID flow? 

 

Thanks

Oz

 


  • matt.maher (Presales - Americas Commercial, Emerging East)

    Hi Ozgur, this sounds like a custom set up that could require Okta Professional Services or a ticket with support. Can you open a support ticket with us to gather more details specific to your environment?
    Selected as Best
  • matt.maher (Presales - Americas Commercial, Emerging East)

    Hi Ozgur, this sounds like a custom set up that could require Okta Professional Services or a ticket with support. Can you open a support ticket with us to gather more details specific to your environment?
    Selected as Best
This question is closed.
Loading
Social IdP's with Provisioning Callout