Handling Conflicting Short Usernames in Okta Classic vs. OIE
Last Updated:
Overview
This article discusses the behavior when handling conflicting short usernames in Okta's Classic and Okta Identity Engine (OIE) environments, specifically when the "Allow short match" setting is enabled. It provides an explanation for the observed behavior in both environments and a recommendation for handling such cases.
Applies To
- "Allow short match" Security Option
- Organization Security
Solution
- In Okta Classic, with the "Allow short match" setting enabled, if there is only one unique active account with a conflicting short username, the user can sign in with the short name.
- However, if another account with a conflicting short username is activated, the short name sign-in will no longer work, and the user will receive an invalid password error, even if all the accounts have the same password.
- For users with conflicting short usernames in different states (active, deactivated, or suspended), the Classic framework will allow the short name login as long as the username prefix is the same as a deactivated or suspended user.
- In contrast, OIE behaves differently. Users with matching Okta username prefixes, even if the conflicting accounts are deactivated or suspended, will not be able to log in using the short name. They must use their fully qualified username to sign in successfully.
