<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Authenticating Active Directory Users to Okta Using Username Prefix
Okta Classic Engine
Directories
Okta Identity Engine
Overview

This article will explain the expected behavior of using a short name for login, described in further detail in Can Users Log in With Only the Username Part of the Email Without Including the Domain while using Active Directory Delegated Authentication with Just-In-Time Provisioning (JIT). 

Applies To
  • Directories
  • Active Directory (AD)
  • Delegated Authentication
  • Just-in-Time (JIT) Authentication
  • Short name
Cause

Under the following conditions, Okta will allow a user to log in with only their username prefix. 

  1. The user attempting to log into Okta is sourced from Active Directory, and Delegated Authentication is enabled.
  2. JIT is enabled.
  3. Multiple users in the Okta tenant can have similar usernames that match short names. For example - userA@abc.com and userA@xyz.com.
  4. The username prefix must be unique within the single domain authenticating the user.
  5. Global Security settings allow short name login.
Solution

To prevent users from logging in with their username prefix:

 

Related References

Loading
Authenticating Active Directory Users to Okta Using Username Prefix