
LachlanW.93990 (Customer) asked a question.
Hello. We have enabled Okta WS-Federation on our office 365 tenant. As AD connect is used on our tenant, admins logging in through Okta get logged into a different account. (aka. instead of user@mydomain.com.au, admins get logged in as user1234@mydomain.onmicrosoft.com). Does anyone know how to fix this? Thanks!

Hi @LachlanW.93990 (Customer)
Okta authenticates users to O365 based on the username from the O365 app in Okta.
As the onmicrosoft.com domains cannot be federated in the first place, there must be some sort of configuration on the O365 side that links the users.
Valentin,
Creat admins new accounts in the domain non mail enabled and use aad or okta to sync them n give them admin leave the onmicrosoft for “break glass” accounts for use only if sso breaks.