Generic OpenID Connect

Generic OpenID Connect (OIDC) allows usersIn Okta literature, we generally refer to "users" as the people who serve as Okta administrators. When we refer to "end users" we are generally referring to the people who the administrators serve. That is, those who use Okta chiclets to access their apps, but have no administrative control. to sign in to an Okta orgThe Okta container that represents a real-world organization. using their credentials from their existing account at an OIDC Identity Provider (IdPAn acronym for Identity Provider. It is a service that manages end user accounts analogous to user directories such as LDAP and Active Directory, and can send SAML responses to SPs to authenticate end users. Within this scenario, the IdP is Okta.). A generic OIDC IdP can be a third-party IdP that supports OIDC, such as Salesforce or Yahoo, or your own custom IdP. You can also configure federation between Okta orgs using OIDC as a replacement for SAMLAn acronym for Security Assertion Markup Language, SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). The SAML standard addresses issues unique to the single sign-on (SSO) solution, and defines three roles: the end user, the IDP, and the SP.. If you want your users to be able to sign in using an existing database of credentials and sync their accounts in to Universal Directory from the external IdP, configure your Okta org to use a generic OIDC IdP.

Features

Configuring a generic OIDC IdP allows you to use the following features:

  • User Registration: Capture the Profile attributes from a generic OIDC IdP user and store those attributes in Okta's Universal Directory.
  • User Authentication: After a user is registered, continue to use that generic OIDC IdP for user authentication, thus eliminating the need to store an additional username and password for that user.
  • Profile Sync: If a user updates their profile, those changes can be reflected inside Okta the next time that they use the IdP to sign in.
  • Support for Multiple Social Profiles: Multiple Social Profiles can all be linked to one Okta user.
  • OAuth 2.0 ScopeA scope is an indication by the client that it wants to access some resource. Configuration: Specify OAuth 2.0 scopes to fully control which attributes are linked to Okta.

For detailed information on usage and set up, see Generic OpenID Connect Identity Providers.

Top