
EdgarsM.73906 (Customer) asked a question.
Hi there.
We have configured inbound SAML - Okta_A is SP and Okta_B is IdP. We have app in Okta_A and we want users from Okta_B to have access to that app. However, what we don't want is to store Okta_B identities in Okta_A. Is that even possible?

Hello Edgars Mazurs,
This is Vasi from Okta Support and I'll try my best to guide here.
The scenario where you have app in Okta_A and you want users from Okta_B to have access to that app, can be achieved but they need to be assigned to the app in Okta_A to that app so they need to be valid user in the tenant . ORG2ORG is an option. You can provision the user directly on your side so they will don't need to login in your Okta_A and use JIT option
Please read the following documentation :
https://saml-doc.okta.com/SAML_Docs/Configure-SAML-2.0-for-Org2Org.html
https://saml-doc.okta.com/Provisioning_Docs/Okta-Org2Org_Provisioning.html
If you need assistance on this configuration please feel free to open a support ticket so we can understand your configuration.