Metadata by URL (if you are using the pre-configured application) or a metadata file (if you are manually adding a SAML 2.0 application) must be used to configure the Identity Provider Metadata Source setting in Jamf Pro's Single Sign-On settings. Copy the metadata file or URL from your Identity Provider.
The metadata from Okta can now be used to configure the Identity Provider Metadata Source setting in Jamf Pro's single sign-on settings. For instructions on enabling SSO in Jamf Pro, see the "Enabling Single Sign-On in Jamf Pro" procedure in the Single Sign-On section of the Jamf Pro Documentation.
Jamf Pro users or end users using enrolled devices may encounter login errors if the Token Expiration Time Override setting is enabled in Jamf Pro. To prevent these errors, you may want to disable the Token Expiration Time Override setting. This will stop Jamf Pro from verifying the token's lifetime, which is controlled by and verified by your IdP. Alternatively, you can ensure that the token expiration time set in Jamf Pro exceeds the expiration time configured by your IdP. However, issues may still occur if the token expiration time dynamically changes.