Glossary
Inbound federation (external IdP)
An Okta configuration that trusts an external identity provider to sign users in; legitimate for partners, and a persistence path in attacker hands.
Inbound federation lets an Okta org accept sign-ins asserted by an external identity provider: a partner's SAML IdP, a social login, or another Okta org. Routing rules and account-linking settings decide which users the external IdP may sign in as. An attacker with admin rights can add an IdP they control and map its usernames to real users, gaining sign-in as those users without their passwords or MFA; this is cross-tenant impersonation. Key events: system.idp.lifecycle.create, system.idp.lifecycle.activate and user.authentication.auth_via_IDP. See rogue IdP persistence.