
ChristopherZ.72522 (Customer) さんが質問をしました。
- Your users can SSO into apps without needing an Okta password.
- You do not need to set up an Active Directory (AD) agent.
- You can connect to a partner.
- You can federate with another IdP.
I only get the last point, which is IDP chaining. In this case Okta is both a SP to an upstream IDP and an IDP to a downstream SP.
As I understand, Okta is not a proxy, and therefore does not proxy traffic to an app. When it gets the SAML assertion from an IDP, what does it do with it?
App traffic will not go through Okta. Is this correct?

Hello,
This is Andrei from Okta support.
Related to the question we will just go ahead pass the SAML assertion from the IDP to the SP.
Also the app traffic will not go through Okta.
If you will require more information you can go ahead and open a support case as well.
Thank you ,
Andrei