Skip to main content

#OKTA0 personne en discute

Hello all, 

 

Has anyone managed to set up their MFA through OKTA. Being that the requirement is in Feb. 2022 we wanted to get a head start by testing, but could not find any supporting documentation to set SF and Okta together for the MFA requirements. 

 

#Security  #MFA  #OKTA

 

Thank you! 

2 réponses
0/9000
Tiffani Sell a posé une question dans #Lightning

While using Okta mobile for Single sign on it only allows my users to log in to salesforce classic with no option to switch to lightning.  Keeping my users in OKTA mobile for SSO and not having them use the Salesforce app, does anyone know how my users can log into lightning?

 

#Lightning  #Mobile  #SSO  #SAML Single Sign On  #Single Sign-On  #Okta SSO  #OKTA  #Okta Login Issue  #OKTA Service Provider  #Sales Cloud

2 réponses
  1. 12 janv. 2022, 08:01

    @Giuliano Zoccoli  I'm facing the same aforementioned issue for one of the users and as mentioned by you all the above permissions have been set but still the same issue.

     

    Any suggestions that might help us. 

0/9000

I have set up SAML Single Sign-On with Okta. I can log in fine using the Identity Provider login url but when I try to log in using Okta on the login screen, I get a Insufficient Privileges error message. I am not sure where I have gone wrong. Any advise?

 

#SAML Single Sign On #OKTA #Sales Cloud #Service Cloud    

1 réponse
0/9000

We have SSO and use Okta. Is the only option to verify on a mobile device? That's not practical as we don't require employees to have a mobile device on hand.

Does Salesforce support any desktop verification method?  If not this is going to kill user adoption.

2 commentaires
0/9000

If we are using a third-party authentication software like Okta, do we still need to enable MFA through Salesforce?

8 commentaires
0/9000

I hope this is the right group to ask in - We're finding a weird behaviour with Single Sign-on and the Redirect policy on My Domain. If we set the Redirect policy to "Redirected with a warning to the same page within the domain" we would expect the warning page only to show up when people use the login.salesforce.com url.

 

However, we're using OKTA, which is set up to use our custom domain and our users still see that warning. This is confusing, as these users are following all the rules and doing everything right, so we'd like them to get logged in immediately.

 

I've raised a case with OKTA, who've stated that they don't think they can control this behaviour: 

"...When using Okta though, the referer is seen as the application URL, in this case it would be https:/domain.okta.com/app/salesforce/<appid>/sso/saml. That is not recognized as the domain so it prompts the warning.

 

That explains why it shows up when using Okta, but unfortunately, we don't knwo if there is anything that can be done in this situation as that is the way all of our apps function."

 

Is there any explanation as to why SSO via OKTA would trip up the login redirect policy?

9 commentaires
0/9000