Okta Generates a "403 Access Forbidden" Error When Navigating to the Login Page
Last Updated:
Overview
After multiple incorrect login attempts, a user receives an error when navigating to the login page. This happens because a password spray event triggers Okta ThreatInsight to block an IP address, resulting in a 403 Access Forbidden error. To resolve the error, wait for Okta to automatically unblock the IP address after 24 hours, or manually unblock it.
403 Access Forbidden
Additionally, searching the System Log using the eventType eq "security.threat.detected" search query displays the following message with the IP address of the user:
Request from suspicious actor Deny
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- ThreatInsight
- System Log
Cause
A password spray event triggers when a user incorrectly guesses a password multiple times. Okta ThreatInsight blocks the IP address to protect the environment.
Solution
How is a blocked IP address resolved?
Okta automatically unblocks the IP address after 24 hours. Review the following article to immediately unblock the IP address.
NOTE: Okta ThreatInsight does not log IPs in the included Network Zones or enforce actions based on the threat level. These IPs proceed to evaluation by sign-on rules. This ensures Okta ThreatInsight does not flag traffic from known, trusted IPs.
