I have configured Confluence (on-prem Server version) to use Okta Single Sign-On (SAML), using these instructions: https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Using_the_Confluence_On_Premises_SAML_App.htm (as well as the configuration instructions generated by Okta during its configuration process).
It works great if I click on the application chiclet in Okta--the user is logged in using Okta and SAML. HOWEVER, if I go directly to the Confluence site, Okta is not invoked at all, and I am able to enter my AD credentials and log into Confluence, as if it had never been configured to use Okta. We want to require users to log in with Okta (among other reasons, it requires Multi-Factor Authentication).
We have also configured our on-premises JIRA server to use Okta in a similar way, and it DOES invoke Okta when the user goes directly to the JIRA URL (this is the behavior we want).
Does anyone know if the behavior I am experiencing with Confluence and Okta is normal and the best I can hope for at this time? Or have I misconfigured something?