<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Generates a "403 Access Forbidden" Error When Navigating to the Login Page

Administration
Okta Identity Engine

Overview

After multiple incorrect login attempts, a user receives an error when navigating to the login page. This happens because a password spray event triggers Okta ThreatInsight to block an IP address, resulting in a 403 Access Forbidden error. To resolve the error, wait for Okta to automatically unblock the IP address after 24 hours, or manually unblock it.

 

403 Access Forbidden

 

403 Access Forbidden

 

Additionally, searching the System Log using the eventType eq "security.threat.detected"  search query displays the following message with the IP address of the user:

 

Request from suspicious actor Deny

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • ThreatInsight
  • System Log

Cause

A password spray event triggers when a user incorrectly guesses a password multiple times. Okta ThreatInsight blocks the IP address to protect the environment.

Solution

How is a blocked IP address resolved?

Okta automatically unblocks the IP address after 24 hours. Review the following article to immediately unblock the IP address.

NOTE: Okta ThreatInsight does not log IPs in the included Network Zones or enforce actions based on the threat level. These IPs proceed to evaluation by sign-on rules. This ensures Okta ThreatInsight does not flag traffic from known, trusted IPs.

 

Related References

Loading
Okta Support - Okta Generates a "403 Access Forbidden" Error When Navigating to the Login Page