Configure routing rules

The default routing rule specifies Okta as the identity provider. You can create a rule for each of your providers or for different combinations of user criteria. When an end user attempts to sign in, the active rules are evaluated. The first one that the user matches is applied.

Before you begin

Before you add routing rules, you need to configure the Okta IWA Web agent and at least one additional identity provider (social identity providers are accepted). See Configure Inbound SAML and Generic OpenID Connect.

If you want to prompt the end user for their Okta username and password on the same page as your list of available identity providers, be sure that the Okta sign-on policy is configured for Password / IDP. This combination is recommended for your rules that offer Okta as an identity provider or if you intend to prioritize the default routing rule.

Note that IdP Discovery on ChromeBook only supports the Okta identity provider and third-party identity providers that have announced support for ChromeBook. Okta Mobile isn't supported for use with Identity Provider Discovery.

Add a rule

  1. In the Admin Console, go to Security > Identity Providers.
  2. On the Routing Rules tab, click Add Routing Rule.
  3. Enter a Rule Name.
  4. Configure the routing conditions.
    IF User's IP isTo specify a zone, at least one network zone must already be defined. For information on zones, see Network Zones.
    AND User's device platform isSelect any combination of mobile and desktop devices. Note that iOS devices may bypass your iOS routing rules. See Configure a routing rule for macOS devices.
    AND User is accessingTo add an application or app instance, start typing the application name. A list of all matching apps appears.
    AND User matchesSelect which login attributes the user must match.
    • Anything includes all users.
    • Regex on login allows you to enter any valid regular expression based on the user login to use for matching. This is useful when specifying the domain or a user attribute is not sufficient for matching. For example, .*\ matches logins for the domain but only if +devtest is included before the @ sign.
    • Domain list on login specifies a list of the domains to match (without the @ sign); for example, It isn't necessary to escape any characters (which is required when using a regular expression).
    • User attributes specify an attribute name, a type of comparison, and a value to match. Note that if you choose Regex for the type of comparison, you must enter a valid regular expression for the value. For example, (Human Resources|Engineering|Marketing) for the Department attribute in your Okta user schema.
    THEN Use this identity providerSelect the identity provider to use when all the criteria are met.
  5. Click Create Rule, and then indicate whether you want to activate the rule immediately.

Configure a routing rule for macOS devices

Due to a change in the way that Safari reports device user agents, Okta can't differentiate between app requests that come from macOS devices and those that come from Safari on iPadOS devices.

To prevent iPadOS devices from bypassing iOS policies, configure a Deny/Catch-All routing rule that applies to macOS and iPadOS devices. To prevent iPadOS device users from being affected by your macOS app routing rules, inform them that they must do one of the following:

  • Option 1: All websites accessed from Safari (iPadOS 13 and higher). In iPad settings, go to Safari settings > Request Desktop Website and then turn off the All Websites setting.
  • Option 2: Per-website basis. Open Safari, tap Aa on the left side of the search field, and then tap Request Mobile Website.
  • Option 3. Access the target app through their Native App or Okta Mobile.

Maintain routing rules

Active rules are evaluated in the order that they are shown on the Routing Rules page. The first active rule that the user matches is applied.


There is no limit to the number of rules you can add. However, routing performance is affected by the number of rules that must be evaluated before a match is found.

  1. To change the priority of rules, hover over the area to the left of a rule number. Drag it into the order you want.
  2. To activate, deactivate, edit, or delete a rule, click the rule name, and then click an action button on the right. You can't modify the default rule.

Related topics

Identity Provider routing rules

Identity Providers