SAML pass through reference architecture
This reference architecture describes the components, flow and similar requires for integrating SAML pass through applications and Access Gateway .
Topics:
Architecture
The SAML pass through architecture is composed of:
- Split DNS: Internal users access the SAML-aware app using the same DNS name as external users. However, the address provided is either the IP address of Access Gateway, for external users, or the IP address of the SAML-aware app, for internal users.
- Okta SAML app: An Okta-based application that's hidden from the user.
- Access Gateway and the Access Gateway application: Proxies SAML requests. The Access Gateway application is hidden from users.
- Okta bookmark application: Used to access the app by users in an Okta org.
Flow
External internet user | Internal user |
---|---|
|
|
Components and requirements
Component | Description and requirements |
---|---|
Okta Access Gateway | All versions of Okta Access Gateway support SAML pass through. |
Access Gatewayapp |
Application defined within Access Gateway, but hidden from everyday users. |
Okta SAML app | A hidden application used by Okta. |
Okta Bookmark app | A book mark application listed in the Okta org. |
SAML Application | An internal SAML application, but using the same name as external references, differentiated by split DNS. |
External URL | External URL specified by the Public Domain field within Access Gateway. Identical DNS to the internal SAML app, differentiated by external DNS. For example: https://saml-app.example.com |