Okta Org2Org Provisioning Error: API Validation Failed Password Requirements Were Not Met
Last Updated:
Overview
An Org2Org provisioning error occurs when the password policy in the Spoke org does not match the password policy in the Hub org during an Org2Org application integration. Resolve this issue by updating the Spoke org password policy to align with the Hub org requirements.
When assigning the Org2Org application to users or groups with the initial status set to active_with_pass or pending_with_pass, Okta displays the following error:
Error while creating user <username>: Api validation failed: password (password: Password requirements were not met. Password requirements: at least 12 characters, a lowercase letter, an uppercase letter, a number, a symbol, and no parts of your username. At least 1 day(s) must have elapsed since you last changed your password.)
NOTE: The highlighted password requirements in the Org2Org provisioning task error message vary based on the Hub org password policy detected in the Org2Org application integration.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Org2Org
- Provisioning with Okta Password Sync enabled
- Org2Org application assignment with initial status set to
active_with_passorpending_with_pass - Mismatched password policies between the Spoke org and the Hub org
Cause
Okta generates a temporary password in the Hub org for new user creation based on the minimum password policy complexity requirement found in the Spoke org. Okta generates an error when the Spoke org default password policy does not match the Hub org password policy requirements.
Assigning an Okta user to the Org2Org application requires setting the Initial status user attribute. This attribute determines the status in the target org when Okta creates, links, or reactivates the user.
When the initial status equals Active with a password or Pending with a password, Okta generates a temporary password. When Okta Password Sync is enabled, Okta overwrites this temporary password when the user signs in.
Solution
How is the Org2Org password requirement error resolved?
Verify the password policies in both the Spoke org and the Hub org, update the Spoke org password policy to match the Hub org requirements, and retry the failed provisioning task.
- Verify whether the Spoke org default password policy requirements apply to the impacted application user.
- Compare the Spoke org password policy with the Hub org password complexity requirements.
- Apply the necessary changes to the Spoke org password policy to align with the Hub org password complexity requirements.
- Retry the failed Org2Org provisioning task from the Spoke org.
