Okta Generates a 400 Bad Request Error Code GENERAL_NONSUCCESS When Attempting a SAML Identity Provider Login
Last Updated:
Overview
When an end user attempts to log in using an external Secure Assertion Markup Language (SAML) Identity Provider (IdP), the login fails because an incorrect SAML IdP configuration exists for the IdP Issuer URI in Okta. Correcting the IdP Issuer URI in the Okta Admin Console to match the Issuer value in the SAML response resolves the issue. The end user experiences a login failure and receives the following error message:
400: Bad Request Error Code: GENERAL_NONSUCCESS
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Secure Assertion Markup Language (SAML)
- SAML Identity Provider (IdP)
Cause
An incorrect SAML IdP configuration for the IdP Issuer URI in Okta causes this error.
Solution
How is the SAML Identity Provider configuration corrected?
Verify the error in the System Log and update the IdP Issuer URI in the Okta Admin Console to match the SAML response.
- Navigate to the System Log and locate the login failure.
- Expand the event if it displays the following message:
Authenticate user via IDP FAILURE: Unable to validate incoming SAML Assertion
- Navigate to System > Debug Context > DebugData > ErrorMessage within the expanded event.
- Verify that the error message displays the following text:
The Issuer in the SAML response did not match the Issuer configured for the Identity Provider.
- Navigate to Security > Identity Providers in the Okta Admin Console.
- Select Actions > Configure Identity Provider for the affected IdP.
- Confirm that the IdP Issuer URI value matches the Issuer value in the SAML response and update it if necessary.
