
kqr44 (kqr44) asked a question.
We have O365 users that are not AD Mastered. Just OKTA Mastered accounts.
They will also be accessing their O365 emails via Outlook WEB.
These users don't have their own computers and will be using desktops where desktop SSO is enabled.
I was lead to understand that these OKTA Mastered accounts will not be able to access their emails from these computers. Is this true and what is a workaround for us.
Thanks.
Fred

Hi Frederick,
Thank you for posting your question on our support page.
Since the specified users are Okta mastered, your users will not be authenticated by the IWA Agents configured for your AD domain, however users can always access the Okta default login by going to https://subdomain.okta.com/login/default to bypass the IWA authentication / authenticate using their credentials.
Regarding your concerns, since your users will use Outlook Web on their web Browser, they will be able to successfully authenticate into Office 365 without extra configuration being needed.
IWA will not interfere with Office 365 unless you've configured Silent Activation for Office 365 to auto-activate Office 365 desktop clients which uses the IWA Agent and users must be AD mastered.
Please find more information in the below KB:
https://help.okta.com/en/prod/Content/Topics/Apps/Apps_O365_Silent_Activation.htm
Therefore, the Okta mastered users will be able to successfully authenticate into your Office 365, however since users will use your workstations that are configured with IWA , you might need to create them AD accounts in order to access the domain joined machines , however since their AD accounts will not be imported into Okta, IWA will not authenticate the specified users and they will have to authenticate using credentials.
If you'll have any questions or require assistance, please open a case with Okta Support.
Kind Regards,
Sergiu Costea
Technical Support Engineer
Okta Global Customer Care