<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00008W2a2USAROkta Classic EngineUniversal DirectoryAnswered2024-04-15T11:36:25.000Z2020-05-15T12:31:19.000Z2020-06-20T13:04:54.000Z

ykhvj (ykhvj) asked a question.

Have Org2Org Identity Provider match against Universal Directory account

We have customers doing an SSO authentication into our target Okta dashboard using inbound SAML 2.0 identity providers. The Identity Provider definition performs JIT to create the user's Okta profile in our hub. That profile is matched with their user account in our Active Directory using Universal Directory. It works great.

However, we now have customers who use Okta on their side which means they must use the Org2Org application on their spoke/source organization to authenticate to our hub/target organization.

Their spoke users can authenticate into our hub Okta dashboard, but their list of applications is empty because instead of creating an AD-mastered Okta profile, our Identity Provider JIT is creating an Okta-mastered user profile for them with no association to their Active Directory user account.

This seemed to work before we purchased Universal Directory.

Any ideas on how to get an inbound SAML Identity Provider in an Okta/Okta Org2Org hub to associate with Active Directory instead of creating a clueless Okta-managed profile?


  • BhaskarM.18336 (Customer)

    i think , instead org2org you can choose inbound saml.? (create saml template in spoke) connects to hub match against attributes

  • ykhvj (ykhvj)

    This same behavior is happening even with normal inbound SAML identity providers: Identity Provider JIT does not do callbacks to our Active Directory.

    It appears that Universal Directory only wants to go one way or the other, not both.

    I also think JIT through an Identity Provider is bound to ONLY working with Okta-mastered user accounts EVEN IF Universal Directory, Active Directory Agents, and AD Delegation is configured in our Okta organization.

    The reason we are using Org2Org is because Okta Support stated that in order to federate between 2 different Okta orgs, a regular inbound SAML Identity Provider will not even accept a connection between to Okta orgs let along implement JIT #sadpanda

     

    Expand Post
  • BhaskarM.18336 (Customer)

    Correct, JIT creats okta mastered accounts not AD mastered - But i also noticed, you said before universal directory - you are able to create AD mastered users via JIT.?? Can you shed some light here.?

  • BhaskarM.18336 (Customer)

    i see how you creating the AD users .

    • Try by whitelist the directory in group level , attached the screenshot
    • also, white list the same group under idp config settings.

     

    directory whitelist

    Expand Post
  • ykhvj (ykhvj)

    This is an interested corner of Directory configuration that I don't understand.

    Before I proceed, I want to make sure and understand:

    1. Adding a single AD group to our Directory won't prevent non-members of that particular group (who currently use Okta) from being able to login or JIT
    2. The Identity Provider can only add users to Okta-mastered groups...I have IdP's adding new members to Okta-mastered group, "Okta SSO Users"
    3. The Directory allows me to add AD-mastered groups to it. Am I to add groups that the users for the dev-349181.okta.com IdP are members of in our compusense.okta.com organization? Is it only going to JIT the user if they are a member to any AD group that is a member of the Directory?

    All these questions are basically so I don't break something simply by adding an AD-mastered group to the Directory. This looks like a promising idea. I just want to make sure I understand it better.

    Expand Post
This question is closed.
Loading
Have Org2Org Identity Provider match against Universal Directory account