
mfug6 (mfug6) asked a question.
Hi,
We use Okta as our IdP which sits in front of our Azure/365 services. Is it possible to add an exception/bypass for certain user accounts so that they authenticate to Azure and not Okta? For example, if the user is a member of a particular group, bypass Okta IdP but authentication to Microsoft instead.
TIA

It is. You will need to onboard Azure AD as a federated IdP and then build a routing rule that will direct relevant users to Azure AD to authenticate. It's a bit circular from a design perspective, but will work just fine.