<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000018Uwhd0ACOkta Classic EngineAuthenticationAnswered2026-01-30T16:59:32.000Z2026-01-06T05:30:48.000Z2026-01-30T16:59:32.000Z

gayeongs.08190 (Customer) asked a question.

Unexpected JIT user creation via SAML IdP even though email domain wasn't in IdP Routing Rule

Hi everyone,

We are using a SAML IdP in Okta, with JIT and automatic group assignment enabled.

The IdP Routing Rule is configured based on domain.

 

For example, if the routing rule only includes the domain 'oktaus.com', users with the domain 'oktakr.com' should not be routed to this IdP, and therefore authentication and JIT user creation should not occur.

 

However in our environment, users with the 'oktakr.com' domain are still being authenticated through this SAML IdP, are JIT-provisioned in Okta, and are assigned to the configured group. (I saw on System Log)

 

What additional areas should I check to understand this behavior?

Are there scenarios where users can be routed to a SAML IdP even if their email domain is not explicitly defined in the IdP routing rule?

 

Thank you.


Loading
Unexpected JIT user creation via SAML IdP even though email domain wasn't in IdP Routing Rule