
q8l7w (q8l7w) asked a question.
Hello There,
i have 2 OKTA Tenant (2 different account in OKTA)
1. x@xxx.com (this we want to consider as master account)
2. y@yyy.com (this is our client account)
Now,
i want to configure y@yyy.com tenant as IDP into x@xxx.com tenant
Questions :
- is it possible ?
- how can i setup it ?
appreciate some help
open for suggestion
Thank You.

I have never done this but it should be possible. Please refer to the below document (org2org) configuration-
https://saml-doc.okta.com/SAML_Docs/Configure-SAML-2.0-for-Org2Org.html
Hello,
i have already gone through this blog but still have few confusion so,
i have created web SAML application into y@yyy.com organisation tenant
question :
what i understood from this blog is
when some user will click on login into x@xxx.com organisation tenant OIDC application at that time
first, request will go to the x@xxx.com organisation tenant and based on IDP route rule user will redirected to y@yyy.com organisation tenant XAML application login and when user get authenticated it will send response to
x@xxx.com organisation tenant Assertion Consumer Service URL and Assertion Consumer Service URL will return response to the x@xxx.com organisation tenant OIDC application
please let me know if i mistaken something.
Thank You for you help tho.
As mentioned above, you can use Org2org with JIT if the user doesn't exist in the destination org.
hello,
can you please suggest how can i get this IdP Issuer URI, IdP Single Sign On URL and IdP Signature Certificate from y@yyy.com organisation tenant web SAML application
Thank You for you help.