Okta - Product admins
42 usersImported identity-provider group
Account settings ยท Security
Connect an identity provider, review workspace access, and test the rollout before requiring SSO for verified company domains.
Connection
Choose the protocol the customer identity provider expects.
Login routing
People using these domains will be routed through SAML 2.0 after activation.
Add verified company domains or begin a DNS ownership check.
Provider metadata
Paste server-issued metadata and keep certificate validation, expiry, and key rotation in the backend.
Paste signed IdP metadata. Store the certificate fingerprint and expiration on the server.
Provisioning
Review imported groups and choose the least-privileged role each group needs before testing access.
Choose imported IdP groups to include in the initial rollout.
Imported identity-provider group
Imported identity-provider group
Imported identity-provider group
Rollout safety
Confirm recovery and communication safeguards before requiring SSO for company domains.
Implementation guidance