
b0pd1 (b0pd1) asked a question.
We have integrated OKTA sso with Cyberark (CA) and Cyberark working as a service provider.We have enabled SAML authentication in CA.User logs into OKTA and then if he clicks CA applicatin user is authenticated and CA is receiving proper SAML responses.But what we noticed for the first time when SAML initiated it gives us "Access denied" error and if we refresh the page it works and user logs into PVWA . Could anyone help me how to fix "Access Denied" error ?

Hello Suresh,
From the looks of it this might be an error or something missing in the SAML assertion.
It would be best if you could contact Okta Support to open up a new ticket as this would require an investigation as it might be an issue with the configuration, mappings, attributes and this would need to be looked in to, also considering doing a Fiddler trace as it would help with the investigation.
Kind regards.
Dorin Melnic