<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Handling Conflicting Short Usernames in Okta Classic vs. OIE

Okta Classic Engine
Okta Identity Engine
Administration

Overview

This article discusses the behavior when handling conflicting short usernames in Okta's Classic and Okta Identity Engine (OIE) environments, specifically when the "Allow short match" setting is enabled. It provides an explanation for the observed behavior in both environments and a recommendation for handling such cases.

"Allow short match" setting

Applies To

  • "Allow short match" Security Option
  • Organization Security

Solution

  • In Okta Classic, with the "Allow short match" setting enabled, if there is only one unique active account with a conflicting short username, the user can sign in with the short name. 
    • However, if another account with a conflicting short username is activated, the short name sign-in will no longer work, and the user will receive an invalid password error, even if all the accounts have the same password.
  • For users with conflicting short usernames in different states (active, deactivated, or suspended), the Classic framework will allow the short name login as long as the username prefix is the same as a deactivated or suspended user.
  • In contrast, OIE behaves differently. Users with matching Okta username prefixes, even if the conflicting accounts are deactivated or suspended, will not be able to log in using the short name. They must use their fully qualified username to sign in successfully.
Loading
Okta Support - Handling Conflicting Short Usernames in Okta Classic vs. OIE