<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008KhMnASAVOkta Classic EngineSingle Sign-OnAnswered2024-04-15T09:04:14.000Z2018-09-12T16:35:09.000Z2018-10-12T19:06:43.000Z

xi800 (xi800) asked a question.

IssuerID Uniqueness per Okta org / Application

Hi,

We are protoyping the usage of Okta to support SSO using SAML.

Our application will be the SP, we will have multiple clients who will register with Okta to function as the IdP.

We assume that each client will have their own Okta Org.

 

We will have at least 2 applications - one used for testing/validation and one used for production. 

 

We would like to validate the following assumption:

 

In response to our applications's SAML authorization request for any user of a specific client Okta Org, the IssuerID in the SAML response will be unique for the combination of: client Okta Org and our Application (but not for the client user) 

 

For example: 

Assuming that we have two instances of our applications called TestApp and ProdApp, and 

Assuming we have 2 client Okta Orgs partnered with us, ClientOrg1 and ClientOrg2.

 

There will be 4 possible IsssuerIDs returned:

IssuerID in SAML responses for any user from ClientOrg1 in TestApp

IssuerID in SAML responses for any user from ClientOrg1 in ProdApp

IssuerID in SAML responses for any user from ClientOrg2i n TestApp

IssuerID in SAML responses for any user from ClientOrg2 in ProdApp

 

Is this a valid assumption? 

 

We wanted to try to test this by creating multiple test Okta Orgs but as our applications have not yet been published, it appears that they cannot be accessed from any other Okta Org. 

 

Apologies if this has been posted elsewhere. The only mention of this which we were able to find of using the IssuerID in this way was an indirect reference in https://developer.okta.com/standards/SAML/*single-idp-vs-multiple-idps

 

Thank you so much for your help!

Krista Campbell

kcampbell@halocommunications.com


  • Hello Krista,

     

    The IssuerID is unique per application, and your assumption is right.

    You can test on one Organization by configuring multiple applications, the same pattern will occur with new Organizations.

    At the SP level, just make sure you support multiple Identity Providers, and everything will work fine.

    If any issues occur, please open a ticket with Support and we will gladly help!

     

    Bogdan Andrisan,

    Customer Support

    Expand Post
    Selected as Best
  • Hello Krista,

     

    The IssuerID is unique per application, and your assumption is right.

    You can test on one Organization by configuring multiple applications, the same pattern will occur with new Organizations.

    At the SP level, just make sure you support multiple Identity Providers, and everything will work fine.

    If any issues occur, please open a ticket with Support and we will gladly help!

     

    Bogdan Andrisan,

    Customer Support

    Expand Post
    Selected as Best
This question is closed.
Loading
IssuerID Uniqueness per Okta org / Application