<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009hcnaiCAAOkta Classic EngineAuthenticationAnswered2023-10-31T21:54:46.000Z2023-10-13T07:26:25.000Z2023-10-31T21:54:46.000Z
Microsoft ecosystem tied to Azure AD and Microsoft trust Okta conditional access : all or nothing

Hello,

 

I have the following issue: Microsoft ecosystem (Exchange Online, Sharepoint online, Teams, Windows 365 etc...) has a strong identity integration with Azure AD (Entra ID). Okta is my main IDP and I have a federation setup for MYDOMAIN.COM.

 

Whenever I connect to Windows365 (for example), AzureAD authentication pops up, I enter john.doe@MYDOMAIN.COM and I'm redirected to Okta for authentication. AFAIK it's not possible to configure Windows365 to use Okta in the first place, the Azure AD step happens in any case. That could be fine, but I would like to setup Conditional Access in Okta to define who can access which (Microsoft) application. I couldn't find how to do this, it seems Conditional Access on Okta will apply to *all* applications linked to Azure AD. I need more granularity on Okta to get the application accessed "before" Azure AD.

 

Is there a trick I missed to achieve this?

 

Thanks,

 

 


  • Hi @User16895844056208209862 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    WS-Fed set up happens at domain level for the Microsoft 365 (Office) app. In this case the app is in fact a suite of apps.  

    The app level sign-on policies would apply to the entire suite, as you mentioned. 

    Currently there is no feature to set up granular access to specific apps from the Okta side.  

     

    You can suggest a Feature Enhancemnt on the Okta Community page by going to the Community Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented. 

    More details here.

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Hi @User16895844056208209862 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    WS-Fed set up happens at domain level for the Microsoft 365 (Office) app. In this case the app is in fact a suite of apps.  

    The app level sign-on policies would apply to the entire suite, as you mentioned. 

    Currently there is no feature to set up granular access to specific apps from the Okta side.  

     

    You can suggest a Feature Enhancemnt on the Okta Community page by going to the Community Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented. 

    More details here.

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Hello,

     

    Thanks for your answer.

     

    I get a blank page when I try to reach the ideas platform. Have you by chance a quick way to turn a forum question into an new idea ?

     

    Thanks

    Expand Post
    • Sorry to hear you are having issues with the Ideas page. I've tested it on both Firefox and Chrome (MacOS) and it's working for me. Please try an incognito window, or a new browser as well (make sure to be signed into the Help Center page first). Maybe disable any ad-blockers if you use any just in case.

      Unfortunately I don't have a way to convert the question to an Idea as they are hosted on a different platforms, but if you continue to experience issues with the site, message me with text of the idea you want to submit and I'll try submitting it on your behalf.

      I'll need the following information:

       

      Idea being requested (idea title): -

       

      What challenges are you experiencing? -

       

      What are you trying to achieve? -

       

      What is your current workaround? -

       

      Additional context to help as we consider your request (optional): -

      Expand Post
This question is closed.
Loading
Microsoft ecosystem tied to Azure AD and Microsoft trust Okta conditional access : all or nothing