
RobM.62038 (Customer) asked a question.
I have configured an okta SAML 2.0 IdP to support our OIDC application for inbound IdP-initiated SSO. When we test with the customer we get the error:
The recipient specified in the SubjectConfirmation did not match our service provider entity id. Found "{0}", expected "{1}"
the URL is:
/sso/saml2/0oa740yy8rMG35uRr357?RelayState=https://pressganey.okta.com/home/oidc_client/0oa16oxmsbp1dkHyz357/aln177a159h7Zf52X0g8
When we take off the RelayState parameter there is no error but we are routed to the okta products page rather than directly to our application. We've used the RelayState parameter successfully in the past to route directly to our application (rather than to okta). Why is it failing this time? Should we be sending RelayState some other way?
Thanks for the help.

Hi @RobM.62038 (Customer) ,
I've escalated your question to our Customer Support team. They will respond to you shortly here.
Thanks!
Tim
Okta, Inc.