After configuring SAML 2.0 authentication, OKTA in this case, accessing IDM will generate an IDM URL with a session token, but never logs into IDM, and you can observe the session information in the URL string being updated repeatedly.
Identity Manager 14.x
In this case, the problem was due to IDM being a cluster behind a load balancer but pointing the "IM Proxy Base URL" at a specific IDM node instead of the overall Load Balancer URL.
Changing the "IM Proxy Base URL" to the fully qualified Load Balancer address resolves this issue: