
m1uva (m1uva) asked a question.
We have currently SWA setup in our environment and we are planning to move to WS-Federation for MFA. Can any one explain me how the authentication works in WS-Federation without user provisioning enable on Okta. Any diagram for authentication cycle would be best help.

Authentication flow on the high level should be similar to SAML. The WS-Federation uses a Request Security Token(RST) and Request Security Token Response(RSTR)). When you access the web application it sends the query in the Request Security token to the Identity Provider. The identity provider will verify the RST and the identity of the user it will send a Request Security Token response back to the application.
If are you planning to use the WS-Federation Template app. You can take a look at our resources to configure the template WS-Federation application.
https://support.okta.com/help/s/article/Configuring-the-Okta-Template-WS-Federation-Application-1608603212
If you are planning to WS-Fed Office 365 the below link is a good place to start.
https://support.okta.com/help/s/article/Configuring-WS-Fed
Neither of these links seem to work for me.
Same, links didn't work for me either. It's blank.
I think this is where the content got moved to:
https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Configuring%20WS-Federation.htm
https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Configure_Okta%20Template_WS_Federation.htm