Skip to main content

I hope this is the right group to ask in - We're finding a weird behaviour with Single Sign-on and the Redirect policy on My Domain. If we set the Redirect policy to "Redirected with a warning to the same page within the domain" we would expect the warning page only to show up when people use the login.salesforce.com url.

 

However, we're using OKTA, which is set up to use our custom domain and our users still see that warning. This is confusing, as these users are following all the rules and doing everything right, so we'd like them to get logged in immediately.

 

I've raised a case with OKTA, who've stated that they don't think they can control this behaviour: 

"...When using Okta though, the referer is seen as the application URL, in this case it would be https:/domain.okta.com/app/salesforce/<appid>/sso/saml. That is not recognized as the domain so it prompts the warning.

 

That explains why it shows up when using Okta, but unfortunately, we don't knwo if there is anything that can be done in this situation as that is the way all of our apps function."

 

Is there any explanation as to why SSO via OKTA would trip up the login redirect policy?

9 commenti
0/9000