<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Troubleshooting "Login denied" Error for Amazon WorkSpaces RADIUS App in Okta

Integrations
Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

Okta generates a login denied error when adding and assigning the Amazon WorkSpaces Remote Authentication Dial-In User Service (RADIUS) application from the Okta Integration Network (OIN) catalog. This issue happens when the Okta username format does not match the Amazon Web Services (AWS) Workspace requirements. Resolve this error by configuring the correct username format in the application sign-on settings and reassigning the users.

 

Login denied. No matching user is assigned to RADIUS App Amazon WorkSpaces.

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Integration Network (OIN)
  • Amazon WorkSpaces Application
  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)

Cause

This error occurs when the username format configured in Okta does not match the requirements of the AWS Workspace. The mismatch between the Okta username and the AWS Workspace username causes Okta to trigger the login denied error.

Solution

How is the Amazon Workspaces RADIUS application login denied error resolved?

 

Configure the correct application username format, enable the User Principal Name (UPN) or Security Account Manager (SAM) account name login setting, and reassign the users with the matching usernames.

  1. Navigate to the Amazon Workspaces App and select the Sign On tab.
  2. Verify the Application username format matches the AWS Workspace requirement, such as a SAM account format.
  3. Locate the Advanced RADIUS Settings section and select Edit.
  4. Select the Enable UPN or SAM Account Name Login checkbox.
  5. Navigate to the Assignments tab.
  6. Unassign all users and reassign them with the correct matching usernames.
  7. Launch the WorkSpaces RADIUS application and attempt a login to verify the resolution.

 

Loading
Troubleshooting "Login denied" Error for Amazon WorkSpaces RADIUS App in Okta | Okta Support