Okta Office 365 SSO User Loop During Authentication
Last Updated:
Overview
An authentication loop occurs when accessing Microsoft Office 365 applications through Okta Single Sign-On (SSO). This issue happens when the "Use Okta MFA for AzureAD" feature is enabled but Okta fails to match the multifactor authentication (MFA) requirements set in Microsoft Azure Active Directory (AAD), or when a user password expires in the local Active Directory (AD) or AAD. Resolve this issue by creating a test authentication rule to verify MFA prompts or by resetting the expired password and clearing the browser cache.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365
- WS-Federation (WS-Fed)
- Single Sign-On (SSO)
Cause
The authentication loop occurs due to one of the following reasons:
- Microsoft enforces a stronger multifactor authentication (MFA) policy than Okta. Microsoft expects two MFA tokens to satisfy the requirement, while Okta only triggers a single-factor authentication rule for the affected user.
- The user password expires in either the local Active Directory (AD) or Azure Active Directory (AAD).
Solution
How is the authentication loop resolved?
Create a test authentication rule in the Okta Admin Console to verify the multifactor authentication flow and ensure the user triggers the correct prompt.
- In the Okta Admin Console, navigate to the Microsoft Office 365 integration.
- Select the Sign On tab and scroll to the bottom of the page.
- Scroll down to User authentication and select View policy details.
- Select Add rule and create a rule with the following mandatory settings:
- User is: Select at least one affected user.
- Client is: Select Web browser or Modern Authentication.
- User must authenticate with: Select any combination from the 2-factor types section.
- Select Save.
- Move the test rule to the first priority position to ensure the user triggers the rule.
- Verify the authentication flow by confirming the multi-factor authentication prompt triggers.
- If the authentication flow succeeds without looping:
- configure the user to trigger existing two-factor authentication rules or
- remove the user from the Conditional Access Policy in Microsoft Azure that enforces multi-factor authentication.
NOTE: Maintaining stronger Microsoft Office 365 authentication policies in Okta than in Microsoft when using the "Use Okta MFA for AzureAD" option prevents access issues.
What steps resolve the loop if the issue persists?
Reset the user password in the local Active Directory, clear the browser cache, and authenticate through an incognito window to resolve persistent authentication loops.
- Reset the user password in the local Active Directory (AD) and synchronize the new password with Azure Active Directory (AAD) to update the credentials in the Microsoft Office 365 portal.
- Clear the cache and cookies from the web browser to remove stored data causing the loop.
- Open an incognito window, sign in to Okta, and select the Microsoft Office 365 application.
- Reset the password again on the Microsoft sign-in page when redirected.
- Sign out of Okta and sign back in to access the Microsoft Office 365 applications.
NOTE: Keeping user passwords up to date and synchronized across platforms ensures seamless access to Microsoft Office 365 applications.
