
MatthewH.10249 (State of Iowa) asked a question.
We provision our WFI users via Org2Org app to our CIAM tenant and want to know if there is a way to restrict them from being able log into Google IDP and force Okta IDP only so that they always remain sourced by Okta AKA Okta Mastered. We still want all users found in our CAIM that are not provisioned from our WFI via Org2Org app to be allowed to be provisioned from any IDP Google, MS, Okta Mastered, etc.

If anyone has a similar need, take a look at using "Auto-Link Restrictions == Specific Groups". We have a group that contains all users expect for the WFI users and we added that group to the "Specific Groups" so they are the only users allowed to use the Google IDP. You can make this change by going to "Security --> Identity providers --> (select Google IDP) Edit IdP --> Advanced Settings".