<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009a2Q85CAEOkta Classic EngineSingle Sign-OnAnswered2024-04-03T16:09:08.000Z2023-09-04T03:17:19.000Z2023-10-18T15:38:17.000Z

MeganN.08084 (Customer) asked a question.

SAML: Can Okta respect the Subject assertion in the SAML Request?

Hey all,

 

I've looked over the documentation, and can't find a way to get Okta to pay attention to a Subject assertion in the SAML request. SAML works fine for a single user, but it appears to break in this scenario:

  1. User initiates login from SP to Okta with one account (1@gmail.com)
  2. User is authenticated and redirected back to SP
  3. User logs out of SP, but Okta session is still in place.
  4. Another user initiates SAML flow from the SP on the same device (2@gmail.com)
  5. This user is redirected to the active Okta session and is logged in and redirected to the first user's account on the SP.

 

It's not desirable to use the Sessions or Auth APIs to fix this flow. It would be helpful if Okta could respect the user information sent over the in the SAML request, knowing to force re-authentication if the subject does not match in the request of the remembered user. Is this at all possible?


This question is closed.
Loading
SAML: Can Okta respect the Subject assertion in the SAML Request?