SharePoint 2019 and OKTA integration

%3CLINGO-SUB%20id%3D%22lingo-sub-3213129%22%20slang%3D%22en-US%22%3ESharePoint%202019%20and%20OKTA%20integration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3213129%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20very%20strange%20problem%3A%20I%20want%20to%20integrate%20OKTA%20as%20Trusted%20Identity%20provider%20in%20SharePoint%202019.%20All%20steps%20provided%20from%20OKTA%20are%20executed%20without%20any%20errors.%20For%20the%20web%20application%20I%20have%20%3CSTRONG%3ENegotiate%20(Kerberos)%3C%2FSTRONG%3E%20and%20%3CSTRONG%3EOkta%3C%2FSTRONG%3E%20as%20Trsuted%20Identity%20Prvider%20as%20shown%20in%20the%20picture.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AuthProviders.PNG%22%20style%3D%22width%3A%20786px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22AuthProviders.PNG%22%20style%3D%22width%3A%20786px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22AuthProviders.PNG%22%20style%3D%22width%3A%20786px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F351206iED8CFE578FBC76DF%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22AuthProviders.PNG%22%20alt%3D%22AuthProviders.PNG%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20I'm%20unable%20to%20authenticate%20neither%20with%20Windows%20Authentication%20nor%20with%20Okta%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22SignIn.PNG%22%20style%3D%22width%3A%20400px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22SignIn.PNG%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22SignIn.PNG%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F351207i1FEB8FB5721EB408%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22SignIn.PNG%22%20alt%3D%22SignIn.PNG%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EWhen%20I%20chose%20Windows%20Authentication%20I%20got%20an%20error%20and%20according%20to%20the%20ULS%20logs%20the%20error%20is%20with%20the%20Identity%3A%3C%2FP%3E%3CUL%3E%3CLI%3EThe%20identity%20is%20not%20in%20format%20we%20recognize.%20IdentityName%3A%20contoso%5Calekspavlov%3C%2FLI%3E%3CLI%3EException%20getting%20user%20key%20string.%20Exception%3A%20'System.ArgumentException%3A%20Exception%20of%20type%20'System.ArgumentException'%20was%20thrown.%20Parameter%20name%3A%20identity%3CBR%20%2F%3Eat%20Microsoft.SharePoint.Administration.Claims.SPClaimUserKeyUtility.GetUserKeyString(IClaimsIdentity%20identity)%3CBR%20%2F%3Eat%20Microsoft.SharePoint.Administration.Claims.SPClaimUserKeyUtility.TryGetUserKeyString(IIdentity%20identity%2C%20String%26amp%3B%20userKey)'.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EWhen%20I%20use%20OKTA%20it%20is%20trying%20to%20authenticate%20me%20but%20at%20the%20end%20sends%20me%20back%20to%20the%20Sign%20In%20page.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%20start%20appearing%20after%20the%20OKTA%20settings%20were%20implemented.%20Before%20that%20Kerberos%20authentication%20was%20working%20just%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWas%20not%20able%20to%20find%20any%20solution.%20Appreciate%20any%20help%20on%20this%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3213129%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESharePoint%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3220054%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%202019%20and%20OKTA%20integration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3220054%22%20slang%3D%22en-US%22%3E%3CP%3EToday%20I%20find%20out%20that%20if%20I%20uncheck%20%3CSTRONG%3ETrusted%20Identity%20provider%20(Okta)%3C%2FSTRONG%3E%20all%20works%20fine.%20So%20looks%20like%20something%20in%20the%20Okta%20configuration%20is%20wrong.%20I%20followed%20all%20the%20steps%20provided%20by%20Okta%20and%20I%20don't%20know%20what%20could%20be%20wrong.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20anyone%20who%20had%20the%20same%20issue%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello everyone,

 

I have a very strange problem: I want to integrate OKTA as Trusted Identity provider in SharePoint 2019. All steps provided from OKTA are executed without any errors. For the web application I have Negotiate (Kerberos) and Okta as Trsuted Identity Prvider as shown in the picture.

AuthProviders.PNG

 

Unfortunately I'm unable to authenticate neither with Windows Authentication nor with Okta

SignIn.PNG

When I chose Windows Authentication I got an error and according to the ULS logs the error is with the Identity:

  • The identity is not in format we recognize. IdentityName: contoso\alekspavlov
  • Exception getting user key string. Exception: 'System.ArgumentException: Exception of type 'System.ArgumentException' was thrown. Parameter name: identity
    at Microsoft.SharePoint.Administration.Claims.SPClaimUserKeyUtility.GetUserKeyString(IClaimsIdentity identity)
    at Microsoft.SharePoint.Administration.Claims.SPClaimUserKeyUtility.TryGetUserKeyString(IIdentity identity, String& userKey)'.

When I use OKTA it is trying to authenticate me but at the end sends me back to the Sign In page.

 

Issue start appearing after the OKTA settings were implemented. Before that Kerberos authentication was working just fine.

 

Was not able to find any solution. Appreciate any help on this issue.

 

Thank you.

2 Replies

Today I find out that if I uncheck Trusted Identity provider (Okta) all works fine. So looks like something in the Okta configuration is wrong. I followed all the steps provided by Okta and I don't know what could be wrong.

 

Is there anyone who had the same issue?

@Aleksandar Pavlov You may have found your answer by now, but apparently OKTA does not yet support SharePoint 2019 according to this:

https://support.okta.com/help/s/question/0D51Y00006N4roNSAR/support-for-sharepoint-2019-onprem-deplo...