I'm currently in the process of migrating our Google Workspace over to Microsoft. My CEO has mandated this move, and while I have my own opinions about it, I'm just rolling with it. Here's the scenario: Our Google Workspace is integrated with Okta SSO, allowing users to access Gmail, Drive, Calendar, and more through Okta. We recently switched our MX and TXT records from Google to Microsoft, but now we're facing a problem when users try to log into Outlook. Instead of configuring their email as an Exchange inbox, it prompts them to add a Gmail inbox. When they select 'continue', it redirects them to Okta for sign-in, which then loads it as a Gmail inbox in Outlook. My question is: Is this happening because Okta is still recognizing the SSO, and since we haven't removed the users from Google, it's mistakenly directing them to the Google Workspace?
5 Answers
You should add the Outlook autodiscover CNAME record along with the MX records. Also, make sure to delete all Google-related DNS records connected to your domain; it’s not just about the MX records.
What you're experiencing seems to be expected. Okta is currently federating the Google identity, which means it’s still routing to Google rather than just handling email. To resolve this, remove the Google Workspace app from Okta or reconfigure the app assignment,
I recommend double-checking your DNS records for the domain in Microsoft 365 and using an external tool like dnsstuff to validate that they’re returning the expected values. You can also use the connectivity checker at office.com to run some tests.
Yeah, it sounds like Okta is still routing users to Google because the Google app is active in Okta. You need to either disable or delete that app from Okta. Another option is to change the authentication priority so Microsoft takes precedence.
I just did a similar migration without Okta, and I noticed Outlook tends to cache authentication details. When entering the email address, try selecting 'set up manually' and then choose Microsoft 365 or Exchange. You could also delete certain folders in the Outlook local app data to clear cached credentials, which might help.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures