<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Returns a 400 Password Expired Error During External Identity Provider Authentication

Single Sign-On
Okta Classic Engine

Overview

When a user in a password-expired state authenticates into Okta via an External Identity Provider (IdP), Okta blocks the login by design and returns a 400 error. To resolve this issue, convert the user to federated mode using the Reset Password Application Programming Interface (API).

 

The user receives the following error:

 

400 PASSWORD_EXPIRED

 

The following screenshot displays an example of the error message.


error example 

 

Personal Identity Verification (PIV) authentication for the same user works without issues.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • External Identity Provider (IdP)

Cause

Okta blocks the login if the users are in a password-expired state.

Solution

How is a user converted to federated mode?

 

Convert the user to federated mode using the Reset Password API.

  1. Use the Reset Password API, passing FEDERATION as the provider parameter.
POST /api/v1/users/<USER_ID>/lifecycle/reset_password?provider=FEDERATION&sendEmail=false
  1. Verify that the user shows as FEDERATED using the GET user information API call.
GET /api/v1/users/<USER_ID>

NOTE: This API may fail if the conversion occurs for an existing account that was previously converted (for example, from ACTIVE_DIRECTORY to OKTA), resulting in an HTTP 400 error and a message similar to the following:

 

Cannot convert user from OKTA to FEDERATION credential provider

 

If this occurs, open a case with Okta Support referencing this article.

 

NOTE: To convert a federated user back to an Okta user, use the default API call.

POST /api/v1/users/<USER_ID>/lifecycle/reset_password?sendEmail=true

Related References

Loading
Okta Returns a 400 Password Expired Error During External Identity Provider Authentication | Okta Support