<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00008cgcf8SAAOkta Classic EngineSingle Sign-OnAnswered2024-04-12T20:09:42.000Z2020-06-01T05:39:29.000Z2020-11-24T11:51:45.000Z

0pd0q (0pd0q) asked a question.

Accessing applications integrated with Okta from Intune MDM

Hi all,

 

We have a few applications integrated with Okta for SSO and they are also deployed on Intune.

 

We have also configured Networks and setup DSSO.

 

Wanted to understand behavior around 2 cases :

  1. When users access these applications from Intune (via browsers)
  2. When users access these applications via mobile

 

Will these flows be treated as SP flows (where applicable)?

 

Thanks much!

Ashwini


  • HI Ashwini,

     

    You are correct, both scenarios are treated as SP-initiated flows from Okta's perspective.

     

    When accessing a URL or a native app, it is expected that the user would be redirected to Okta for login, when the flow is supported. Mainly, the SP endpoint should support the redirection to Okta for authentication. The concept is more detailed here, in the "Planning for SAML" section:

     

    https://developer.okta.com/docs/concepts/saml/

     

    Additionally, if the SP-initiated flow isn't supported, you can use the app's embed link to trigger the SSO, or if the reverse is true, that is, if the IdP-initated flow is not supported, you can use a Bookmark App as described here:

     

    https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Bookmark_App.htm

     

    I hope this helps!

    Expand Post
    Selected as Best
  • HI Ashwini,

     

    You are correct, both scenarios are treated as SP-initiated flows from Okta's perspective.

     

    When accessing a URL or a native app, it is expected that the user would be redirected to Okta for login, when the flow is supported. Mainly, the SP endpoint should support the redirection to Okta for authentication. The concept is more detailed here, in the "Planning for SAML" section:

     

    https://developer.okta.com/docs/concepts/saml/

     

    Additionally, if the SP-initiated flow isn't supported, you can use the app's embed link to trigger the SSO, or if the reverse is true, that is, if the IdP-initated flow is not supported, you can use a Bookmark App as described here:

     

    https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Bookmark_App.htm

     

    I hope this helps!

    Expand Post
    Selected as Best
    • 0pd0q (0pd0q)

      Hi @sebastian.petroi1.5665717802357122E12 (Vendor Management)​  - We have an environment with multiple forests. There is one way trust on one forest to all other forests. We have installed AD agents in all the domains for Delegated auth and have enabled agentless DSSO

       

      Now, we want to enable Device trust, for which the pre-req is to install IWA agent.

       

      Could you please help me with responses to the following :

      1. How many IWA web agents do we need? Is it based on the number of forests i.e. 1 IWA Agent/forest? I have looked for documentation on this, but was unable to find.
      2. How does IWA agent help with Device Trust in enrolling the devices ? The document is not clear.
      3. How can we decide the number of primary and backup IWA agents?
      4. Is the primary enough for all forests to enroll devices?

       

      Thanks,

      Ashwini

      Expand Post
This question is closed.
Loading
Accessing applications integrated with Okta from Intune MDM