> Can someone explain why people still choose Okta? I personally feel way more comfortable using GSuite as an IDP.
GSuite as an IDP is very very limited. Sure, it checks that box as "Yes, is IDP"
However if you want to do much beyond "can connect", it's either difficult or impossible.
Take for example you're an organisation that has all employees in GSuite.
You also have an AWS organisation, and need to provide access - well, AWS SSO[1] is the recommended way to do this. I set up the connection, and people can now connect.
However there's some gaps:
There's no automatic user [de]provisioning into AWS SSO, based on GSuite user groups. (You could write some code to do this via the SCIM support in SSO, but you have to maintain it)
There's no way on either the GSuite or AWS SSO side to enforce an MFA check when the SSO session is being set up.
GSuite doesn't let you require an MFA check before authenticating to SAML applications.
AWS SSO doesn't allow forcing MFA check when using an IDP, even though it does if you use it's internal Directory.
Okta, and similar products (can) do those things for you, and allow some of those MFA checks to be based on what endpoint is being used. At least according to their marketing materials and sales people. I've never actually done it myself.
I guess the tl;dr is that Okta provides a lot more options for automation and security glue between the identity provider and consuming application(s).
[1] When I say AWS SSO, I mean specifically the AWS product: "AWS IAM Identity Center (Successor to AWS Single Sign-On)"