Prompt
What’s the best way to support Okta and Azure AD in one app?
Latest observation
The best pattern is usually to abstract authentication behind a single identity layer in your app, and support both Okta and Azure AD via OIDC/OAuth 2.0 rather than building provider-specific logic everywhere.
Recommended approach
1. Use OpenID Connect for both
Both Okta and Azure AD / Entra ID support OpenID Connect. That gives you:
- a common login flow
- consistent identity claims (
sub,email,name, groups/roles if configured) - easier token validation
- less vendor-specific code
2. Build a provider-agnostic auth module
Create an internal auth service/module that handles:
- redirecting to the correct IdP
- handling the callback
- exchanging auth code for tokens
- validating ID/access tokens
- mapping external users to your app’s user model
Then keep the rest of the app unaware of whether the user came from Okta or Azure AD.
3. Support tenant/org selection
If you have users from multiple companies, you’ll likely need one of these:
- email domain routing (e.g.
@customer.com→ Azure AD,@partner.com→ Okta) - a “Sign in with…” selector
- an IdP discovery step based on email/domain
4. Normalize claims into your own model
Don’t rely on provider-specific claim names directly in the app. Map them into something like:
userIdemaildisplayNamerolestenantIdidentityProvider
This helps when Okta and Azure AD return different claim shapes.
5. Use standard authorization in your app
For app permissions, prefer:
- your own roles/permissions model, or
- groups/roles synced from the IdP
But don’t hardcode business logic to “Okta group X” or “Azure role Y” unless absolutely necessary.
Two common architectures
Option A: Direct federation from app to both IdPs
Your app can support two OIDC configurations:
- Okta issuer/client
- Azure AD issuer/client
Then choose the provider at login time.
Good for: smaller setups, few tenants
Downside: more logic in the app, more config management
Option B: Use a central broker/identity platform
Use an identity broker like:
- Okta as a broker
- Azure AD B2C / Entra External ID
- Auth0 / Keycloak / other IdP broker
Your app only integrates with one provider, and that broker federates to Okta and Azure AD.
Good for: multiple IdPs, B2B SaaS, easier app integration
Downside: extra platform dependency/cost
Practical recommendation
If you’re building a SaaS app for multiple customer orgs, the most maintainable approach is usually:
- OIDC for both
- provider discovery
- a normalized internal user model
- optionally an identity broker if you expect many orgs/providers
Security best practices
- Use Authorization Code Flow with PKCE
- Validate issuer, audience, signature, nonce, and exp
- Store tokens securely; prefer server-side sessions if possible
- Use short-lived access tokens and refresh tokens only when needed
- Separate authentication from authorization
If you want, I can also sketch:
- a recommended architecture diagram, or
- a sample implementation for React/Next.js, Node, .NET, or Java.