<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006wnSxKCAUOkta Classic EngineIntegrationsAnswered2024-04-16T11:53:41.000Z2021-04-30T15:37:59.000Z2021-10-13T21:17:47.000Z

1fj3q (1fj3q) asked a question.

Using Okta for Hybrid AAD Join Windows Hello for Bussiness

We have M365 in our environment with Okta as an IDP. We have existing Okta signOn policies for Mobile and Non-Mobile devices. Both these devices use InTune for device management. Mobile devices SignOn policies are working fine and for non-mobile devices we have existing signOn policy to prompt for MFA is user is trying access M365 apps outside of corporate network which works fine until we recently started to also AAD domain join these devices. The process to AAD domain join require user to start Windows AutoPilot. Windows AutoPilot process require one time MFA during PIN create step. Since existing Okta SignOn Policy doesn't require MFA for users trying to authenticate within the corporate network and there is nothing in the Request Headers which can be used to differentiate this particular scenario through Okta SignOn policy as a result user goes into infinite loop as Azure is expecting MFA claim but Okta is not promptingf or MFA because user is within corporate network. We contacted Microsoft and they said, the only way to differentiate is using query string URL send in the original redirect url to the IDP but there is no policy which can be created based on the WF-fed query string url. We are at a stand still and would like to know if there is any workaround and it's big thing for large enterprises like ours.

 

We opened Support ticket but haven't been able to get positive response which is surprising.

 

Any help is highly appreciated!


  • User15869520088343348455 (Vendor Management)

    I will recommend to escalate the case if necessary and involve you Account Executive to get desired traction.

  • 5za19 (5za19)

    You need to add supportsmfa=true to your federation settings.

This question is closed.
Loading
Using Okta for Hybrid AAD Join Windows Hello for Bussiness