Configure Okta as Identity Provider on AVS vCenter

Fabrice Bastian 20 Reputation points
2025-07-31T10:00:03.14+00:00

Hello,

I wanted to know if there is a way to configure Okta as Identity Provider for an Azure VMware Solutions cluster (configure vCenter SSO Identity Provider with Okta).

I currently only see LDAP as a valid one in the provided packages.

Thank you for any inputs regarding this.

Best regards

Fabrice

Azure VMware Solution
0 comments No comments
{count} votes

Answer accepted by question author
  1. Jerald Felix 8,625 Reputation points
    2025-07-31T10:04:42.98+00:00

    Hello Fabrice Bastian!

    To configure Okta as an Identity Provider for Azure VMware Solution (AVS) vCenter SSO:

    Currently, vCenter Single Sign-On (SSO) in AVS supports:

    • Microsoft Active Directory (LDAP/LDAPS)

    Identity sources compatible with LDAP/SAML (in on-prem vCenter)

    However, direct integration with Okta (as a native identity provider) is not supported out of the box in AVS-managed vCenter at this time; only LDAP-based identity providers are shown in the native packages.

    Possible Workaround:

    If your Okta setup allows, you may be able to configure Okta Universal Directory to act as an LDAP interface, then add it to vCenter as an LDAP identity source.

    Alternatively, use Okta to synchronize users/groups into an Azure AD or on-prem AD which is then integrated with vCenter.

    Summary: You cannot configure Okta as a native SAML/SSO IdP directly in AVS vCenter at this time. Your best option is to leverage Okta's LDAP interface or synchronize with AD.

    If you need help with a specific integration method or Okta LDAP interface setup, let me know!

    Best Regards,

    Jerald Felix

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Fabrice Bastian 20 Reputation points
    2025-07-31T12:15:33.84+00:00

    Hello Jerald,

    Thank you very much for the quick and detailed answer.

    This was quite of my initial assumption regarding limitation on the Identity Provider configuration.

    It's clear now and we will check for the best solution on our side.

    Best regards

    Fabrice Bastian

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.