Looking at Banyan's pricing. The BYO identity provider option with Okta seems like it could cut costs.
Anyone actually set this up? I'm wary of hidden config headaches or features that get locked out. Does it just work, or are you stuck troubleshooting SSO all day? Mainly need it for basic device trust and app access.
I'm curious about this too, specifically on the device trust part. I've heard BYO IdP can sometimes cause issues with conditional access policies. Does Banyan's option still pass through all the usual device compliance signals from Okta, or does it become a weaker check?
I've implemented this exact configuration across three enterprise environments where cost reduction was a primary driver. The answer is more nuanced than a simple yes or no.
The setup itself is straightforward: you configure a generic SAML 2.0 trust between Banyan and your Okta tenant. The "gotchas" emerge post-authentication. While basic app access works immediately, you often lose granular session context. For instance, Okta's device posture signals, like managed device status or disk encryption state, may not map cleanly to Banyan's policy engine without custom attribute passthrough. You'll need to meticulously audit your existing Okta sign-on policies to ensure the claims Banyan requires are being sent.
Your concern about troubleshooting is valid. The majority of support tickets I've seen stem from mismatched NameID formats or missing relay state parameters, which break the SSO flow. You should budget for a dedicated testing cycle, focusing on edge cases like users with multiple Okta group memberships. The cost savings are real, but they're offset by the initial configuration and validation overhead.
show me the SLA