<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006aDfJbSAKOkta Classic EngineAdministrationAnswered2019-10-24T18:29:56.000Z2019-08-26T09:00:43.000Z2019-10-24T18:29:56.000Z

GilK.69845 (Customer) asked a question.

ADFS inbound access IPs list

Hello,

In this article https://help.okta.com/en/prod/Content/Topics/Security/Firewall_Whitelisting.htm

There's a link to a list of Okta IPs to whitelist.

We're looking to simulate a federation with ADFS in a lab environment, but our organization has pretty hard security requirements.

Is it possible to narrow down the list of IPs, or provide an IP range from where Okta accesses ADFS?


  • isthatDinu (Okta, Inc.)

    Hi Gil,

     

    I'm afraid we won't be able to narrow down the list of IPs/IP ranges to where Okta accesses ADFS. What we could narrow the list down to would be the cell that you have the Okta org on, and add those IP addresses to the whitelist, just to avoid adding IPs that are not necessary to be whitelisted. To check what would be the cell that your org is placed in, log into the Okta Admin Dashboard and scroll down all the way to the bottom, where you will find the current version of Okta as well as the Cell that your org lies under. After figuring out what cell you're in, access https://s3.amazonaws.com/okta-ip-ranges/ip_ranges.json and do a CTRL+F for "cell". I hope this helps.

     

    Thank you,

    Marius Dinu

    Okta T2 Support Engineer

     

    I hope this helps.

     

    Expand Post
    Selected as Best
  • isthatDinu (Okta, Inc.)

    Hi Gil,

     

    I'm afraid we won't be able to narrow down the list of IPs/IP ranges to where Okta accesses ADFS. What we could narrow the list down to would be the cell that you have the Okta org on, and add those IP addresses to the whitelist, just to avoid adding IPs that are not necessary to be whitelisted. To check what would be the cell that your org is placed in, log into the Okta Admin Dashboard and scroll down all the way to the bottom, where you will find the current version of Okta as well as the Cell that your org lies under. After figuring out what cell you're in, access https://s3.amazonaws.com/okta-ip-ranges/ip_ranges.json and do a CTRL+F for "cell". I hope this helps.

     

    Thank you,

    Marius Dinu

    Okta T2 Support Engineer

     

    I hope this helps.

     

    Expand Post
    Selected as Best
  • GilK.22031 (Customer)

    Thanks for the answer!

    I realized that my question is probably pretty stupid, since Okta doesn't actually perform any direct communication with ADFS, rather performing all of it through the user agent.

This question is closed.
Loading
ADFS inbound access IPs list