
avshch (BCRC) asked a question.
Tenable Security Center SSO with Okta
Hello,
Has anyone implemented SSO between Okta and Tenable Security Cetner (On-Prem) as per the following article?
https://docs.tenable.com/security-center/Content/SAMLAuthentication.htm
sp-initiated auth flow seems to be working, but having an issue with idp-initiated auth flows.

Hello @avshch (BCRC) Thank you for posting on our Community page!
You are asking whether anyone has successfully implemented SSO between Okta and Tenable Security Center (on-premises) using the SAML authentication flow documented by Tenable, and whether there are known issues with IdP-initiated authentication flows when SP-initiated flows are already working.
IdP-initiated SAML flows are supported by Okta, but they require specific configuration on both the identity provider (Okta) and service provider (Tenable Security Center) sides. The fact that SP-initiated flow works but IdP-initiated does not suggests a mismatch in how Tenable Security Center is configured to handle unsolicited SAML assertions or RelayState parameters.
Root Cause:
IdP-initiated flows differ from SP-initiated flows in a critical way: the user initiates login directly from the Okta dashboard (or a direct link to Okta's assertion consumer service endpoint), and Okta sends a SAML response without a prior authentication request from the service provider. Tenable Security Center may not be configured to accept unsolicited assertions, or it may require specific RelayState handling that differs from the SP-initiated setup.
Solution:
Follow these steps to troubleshoot and configure IdP-initiated authentication:
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.