<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000A9kxS4CQIOkta Classic EngineAuthenticationAnswered2024-06-28T20:46:01.000Z2024-06-10T20:58:19.000Z2024-06-28T20:46:01.000Z

GeorgeB.25972 (Customer) asked a question.

External Onedrive sharing folder with user from federated Microsoft tenant with okta

We're running into a jam with a company we do business with, but are not connected to with our Okta environment, which is federated with a microsoft tenant with a few domains. Everyone in our org has a microsoft account connected to one of our domains, and I'll call that Domain A. We also have microsoft accounts set up with the company we do business with on their tenant and domain, which I'll call Domain B. Domain B is only accessible from inside their citrix environment.

 

When we try to share a link from Domain B's onedrive to our Domain A account, we get the email just fine about the sharing in the Domain A account's inbox. Clicking the link will from that inbox creates a verification back to Domain A's Okta to verify who we are to Domain B. Domain A's Okta verifies who we are, but has no way to send us back to Domain B's tenant to finish the share, so it continually loops.

 

This happens on more than just Onedrive. We will also receive secure emails from Domain B, specifically for a person in Domain A. They can never get to it, because when they attempt to verify it gets stuck in that loop, and never sends us back to Domain B.

 

If we receive any of Domain B's share invites or secure emails to a separate domain, on a Microsoft tenant not federated with our Okta or connected to Okta at all, it works fine. I can't share from Domain A user's onedrive to Domain B, because their firewall restricts our netorg's sharepoint domain.

 

Wondering if anyone has seen this behavior or knows of a fix for our Okta config. Thank you.


  • Hello @GeorgeB.25972 (Customer)​ Thank you for posting on our Community page!

     

    The issue here is the Domain B's Firewall, one thing that you could do is to ask Company B to whitelist Company A's IP's or to use a shared VPN with IP's Whitelisted in both environments.

    Please also see our networking zone doc:

    https://help.okta.com/en-us/content/topics/security/network/network-zones.htm

     

    Thank you for reaching out to our Community and have a great day!

    --

    Join the Ask Me Anything online event on June 13, 2024 to discuss the new Govern Okta Admin Roles feature with our Experts 

    Expand Post
    Selected as Best
  • GeorgeB.25972 (Customer)

    Hey Paul

    Thanks for the info- VPNs aren't allowed, and whitelisting on their side is not an option. I think I did a poor job explaining the issue, but the solution was in our setup. Our office365 connection through Okta was to blame. Okta was using 2FA to verify people, then passing it on to Office365. Office365 was just recognizing single factor authentication (through the azure logs). The problem was in Company B's Office365 requiring 2FA, and our Okta supplying single factor authentication, prompting the never ending verification cycle. I had to create a new group in Okta and our Azure requiring 2FA for just Office365, then put myself and the other people requiring this in it. After doing that, the handoff worked, and we can accept onedrive share requests and links from Company B's office365. I hope this saves somebody some time in the future.

    Expand Post
This question is closed.
Loading
External Onedrive sharing folder with user from federated Microsoft tenant with okta