
bowfb (bowfb) asked a question.
We have IIS hosting a website and would like to protect it with Okta. Is there a way we can authenticate the incoming request into IIS to route to Okta for authentication? Once Okta successfully authenticates, IIS will route to the website. Please let me know if this is feasible.
Thanks
Raj

Hi Raj,
You need OKTA Access gateway to protect your On-premise or hosted application. That is a separate module & act as a Policy Enforcement point (PEP) to your On-premise web application. Okta Access Gateway has a SAML integration with your OKTA ORG Domain & it can inject headers from the SAML assertion & pass it to your application. I am attaching a sample architecture here for reference. It will give you a better understanding. I hope it helps.