Entra App Passing Through Wrong Federated Endpoint

jbjahn 0 Reputation points
2025-05-07T19:02:10.0466667+00:00

We are using Okta IDP and have a federation with M365. We have a service provider we are integrating with that uses Entra as their identity provider. When we attempt SP-initated SSO, we are prompted to enter our username into a login.microsoft.com prompt which then passes us through our IDP as expected. Unfortunately, we are passed through our M365 Okta federation rather than the service provider integration in Okta. It seems as though Entra is doing some sort of domain discovery and based on the domain entered with our username, Entra is looking up that domain and seeing there is an existing federation in place and it uses that rather than the correct service provider integration we have setup. The app doesn't appear to support IDP-initiated otherwise we would opt for this route. Anyone run into anything like this?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,553 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.