<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Get Password Expired: 400 Status when Providing Valid Authentication via External IDP
Single Sign-On
Okta Classic Engine
Overview

When a user is in a Password Expired state in Okta, and the user authenticates via External IdP into Okta, the user receives an error:

 400 PASSWORD_EXPIRED

 

PIV authentication for the same user works without issues.
 

Applies To
  • External Identity Provider (IdP)
Cause
This is working by design; Okta will block the login if the users are in a password-expired state.
 
Solution

If users do not have a password, once they are migrated to the External IdP to authenticate into Okta, convert them into federated mode.

Once the users are converted to federated mode, they will not require a password in Okta if they can authenticate via external IdP.

 

Related References

Loading
Get Password Expired: 400 Status when Providing Valid Authentication via External IDP