Okta Returns a 400 Password Expired Error During External Identity Provider Authentication
Last Updated:
Overview
When a user in a password-expired state authenticates into Okta via an External Identity Provider (IdP), Okta blocks the login by design and returns a 400 error. To resolve this issue, convert the user to federated mode using the Reset Password Application Programming Interface (API).
The user receives the following error:
400 PASSWORD_EXPIRED
The following screenshot displays an example of the error message.
Personal Identity Verification (PIV) authentication for the same user works without issues.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- External Identity Provider (IdP)
Cause
Okta blocks the login if the users are in a password-expired state.
Solution
How is a user converted to federated mode?
Convert the user to federated mode using the Reset Password API.
- Use the Reset Password API, passing
FEDERATIONas the provider parameter.
POST /api/v1/users/<USER_ID>/lifecycle/reset_password?provider=FEDERATION&sendEmail=false
- Verify that the user shows as
FEDERATEDusing the GET user information API call.
GET /api/v1/users/<USER_ID>
NOTE: This API may fail if the conversion occurs for an existing account that was previously converted (for example, from ACTIVE_DIRECTORY to OKTA), resulting in an HTTP 400 error and a message similar to the following:
Cannot convert user from OKTA to FEDERATION credential provider
If this occurs, open a case with Okta Support referencing this article.
NOTE: To convert a federated user back to an Okta user, use the default API call.
POST /api/v1/users/<USER_ID>/lifecycle/reset_password?sendEmail=true
