Okta Service Provider Flow Error 403 User Attempted Unauthorized Access To App
Last Updated:
Overview
An error occurs during a Service Provider (SP) initiated login flow when a user attempts to access an application without a complete or active assignment in Okta. Resolve this by verifying the application's assignment status and reassigning it to the user.
When a user attempts to access a specific application during the SP-initiated login flow, Okta generates the following error:
403 App Not Assigned
Sorry, you cannot access <app name> because you are not assigned this app in Okta. If you're wondering why this is happening, please contact your administrator.
Additionally, Okta generates the following error in the System Log, where the actor is the impacted user and the target is the application instance:
User attempted unauthorized access to app failure:
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Service Provider (SP) Initiated Application Sign-On
- Secure Web Authentication (SWA)
- Security Assertion Markup Language (SAML)
- WS-Federation Single Sign-On (SSO)
- Okta Integration Network (OIN)
Cause
This error occurs due to a missing or incomplete application assignment caused by specific application assignment or provisioning errors for the impacted user in the Okta Admin Console.
Confirm the root cause by checking the user list of assigned applications under the Applications tab in the user profile.
Alternatively, check the affected application in the Assignments tab to see if Okta lists the user with any errors.
Solution
How is the unauthorized access to application error resolved?
Resolve the unauthorized access error by verifying the application assignment status in the System Log and reassigning the application to the user by following these steps.
- Verify the root cause of the issue by checking the System Log and the application assignment status of the impacted user.
- Reassign the affected application to the user in Okta and ensure there are no application assignment errors or provisioning task errors if the application has provisioning enabled. For full details, review the Assign an app integration to a user documentation.
- Instruct the user to attempt the application sign-on again once the user has an active application assignment.
