
OlegT.09904 (Customer) asked a question.
We have SSO with external SAML idp. When an authenticated user redirected to OKTA we expect that a new user will be created and logged in, but instead user gets a page with a challange to enter a password or an authentication code.

Hello @OlegT.09904 (Customer) Thank you for reacting out to our Community!
This would be expected behaviour as the application has a MFA sign on policy. So every-time they access the app they need to use MFA get access.
The Okta Community Catalysts Program is now live. Collect online badges when you participate in the Okta Help Center Questions community. Learn more here.
Community members help others by clicking Upvote or Select as Best on responses. Try it today.