<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000AJPLRXCQ5Okta Classic EngineSingle Sign-OnAnswered2025-01-29T20:58:04.000Z2025-01-22T13:09:02.000Z2025-01-29T20:58:04.000Z
Preserving Username in SAML AuthRequest When Forwarding from Okta to External IdP

Hello community,

Use case: We have an application that uses okta for SSO with SAML2.0. The authentication flow is:

The application (original SP) sends a SAML auth request to okta, including the username in the SAML subject. Okta, based on the routing rules, forward this request to an external IDP, which authenticates the user via a security/hardware key.

 

Problem:

The username from the original SP's SAML authrequest does not appears to be forwarded to the external IDP by okta. As a result, the user has to enter their username again at the external IDP, which we want to avoid.

 

Questions:

a) How can we configure Okta to preserve and forward the username from the orignal SAML authrequest to the external IDP?

b) What are the best practises or configuration steps within okta to ensure the username is correctly passed through?

c) Are there specific logs or debugging tools inn Okta that can help us trace and ensure the username attribute is managed properly?

 

Current configuration:

a) The original SP sends the username in the SAML subject to okta.

b) Okta applies routing rules to forward the request to an external idp.

c) The external idp requires re-entry of the username for authentication via security key.

 

Any detailed guidance on achieving this would be greatly appreciated. Thank you!!!


This question is closed.
Loading
Preserving Username in SAML AuthRequest When Forwarding from Okta to External IdP