
SvcBancsAPITestT.08169 (Customer) asked a question.
We have a custom SAML app that uses okta for client authentication.
One of our clients wants to explicitly restrict the URLs they let their employees have access to.
They tried whitelisting our okta domain, but say they still have issues.
How can I supply them with a full list of subdomains they will have to whitelist?

This article includes the Okta domains you may need to whitelist: https://help.okta.com/en-us/Content/Topics/Security/ip-address-allow-listing.htm