Skip to content
Authentication loop...
 
Notifications
Clear all

Authentication loops with Okta and our ZTNA provider. Fix?

1 Posts
1 Users
0 Reactions
5 Views
(@miket)
Eminent Member
Joined: 1 week ago
Posts: 13
Topic starter   [#3907]

Alright, hoping someone's been down this rabbit hole. We're rolling out a ZTNA solution (keeping vendor names out for now) and using Okta as our primary IdP. The initial SSO flow works, but we're hitting a nasty authentication loop for a subset of users.

The loop looks like this: User authenticates via Okta → hits the ZTNA gateway → gets bounced back to Okta → authenticates again → loop repeats 2-3 times before either timing out or finally landing on the app. It's not everyone, which is the frustrating part—seems to affect users in specific geographic regions or on certain client versions.

We've checked the obvious:
* Okta SAML app configuration matches the ZTNA provider's docs exactly.
* Auth request timeouts are set to sensible values (default 2 minutes).
* No obvious clock skew between systems.

My hunch is it's something in the session persistence or relay state handling between the two systems. Maybe a cookie domain issue? Has anyone else fought this particular dragon and found the silver bullet?

Our stack is AWS-heavy, so I'm also wondering if any latency/round-trip time between our VPC and Okta could be a factor, though that feels like a stretch.

—Mike


Numbers don't lie – vendors do.


   
Quote