
ANDREAS.76463 (Customer) asked a question.
Hi,
is it possible to authenticate OKTA users from external IDP (e.g. AzureAD)?
In particular I would like to use our internal IDP to authenticate and provide access to OKTA's admins.
I don't want provide access to an external application but only to OKTA admin console.
Thanks
BR
Andrea

Hi, @ANDREAS.76463 (Customer)
Thank you for posting on our Community page!
You can add the admins you want to be authenticated via IdP in a group and create an MFA policy applicable to that group only:
https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-idp-authenticator.htm
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/create-mfa-policy.htm
_____________________________________________________________________________
Ask the Experts: Now Thru 1/31 Okta FastPass Engineering and Product Teams Answer Your Questions
Community members help others by clicking Like or Select as Best on responses. Try it today.
_____________________________________________________________________________
Thanks for your answer.
I have configured it but now I have a "Unable To JIT" error.
I saw several topic about this error.
It seems Okta requires attributes are being saved to the IDP profile. But how can see what are the attributes that are needed to OKTA?
I was expecting a more verbose error message like "this parameter is needed".
Thanks
BR
Andrea
Hi @ANDREAS.76463 (Customer) ,
Unless you have configured additional attributes as “required”, the mandatory Okta profile attributes are as follows: Username, First Name, Last Name, and Primary Email.
You might be able to leverage the Okta System Logs to review the failed authentication event and if you expand it to see all details, I’ve seen situation where it states what attribute is missing.
Details about System Logs here: https://help.okta.com/en-us/content/topics/reports/reports_syslog.htm
Regards.
--------------------------------
Ask the Experts: Now Thru 1/31 Okta FastPass Engineering and Product Teams Answer Your Questions