Okta Org2Org Password Sync Fails With Invalid Credentials Error
Last Updated:
Overview
Okta generates an invalid credentials error when a user attempts to sign in to a Hub organization using a Spoke organization password because the initial Org2Org application assignment only synchronizes a randomly generated password. Signing in to the Spoke organization manually with the Okta password triggers a password synchronization update, resolving this issue. The following errors appear during sign-in when administrators enable the Sync Okta Password feature:
However, it may be noticed that when a user tries to log in to the Hub org with the Spoke org's Okta Password (which should be synced over from the Spoke org), the Hub org's Okta user account returns a login failure due to INVALID_CREDENTIALS.
The end-user is seeing:
Unable to sign in
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Integration Network (OIN)
- Org2Org Provisioning
- Password Synchronization
- Federated Single Sign-On (SSO)
- Integrated Windows Authentication (IWA)
- Active Directory Desktop Single Sign-On (ADSSO)
Cause
The error occurs because the initial Org2Org application assignment only synchronizes a randomly generated password based on the applied Okta password policy. If administrators set the initial status to active with password or pending with password, Okta generates a temporary password for the user. Okta does not synchronize the actual Okta password to the Hub organization user account until Okta detects a manual password sign-in in the Spoke organization.
NOTE: The user must perform a manual Okta password sign-in. If the user signs in to the Spoke organization via Federated Single Sign-On (SSO) or Integrated Windows Authentication (IWA) Kerberos sign-in, Okta does not utilize the Okta password and fails to trigger the password synchronization update to the Hub organization.
Solution
How is the Org2Org invalid credentials error resolved?
Instruct the user to sign in to the Spoke organization manually using the Okta password to trigger a password synchronization update to the Hub organization.
- Instruct the user to sign in to the Spoke organization using the Okta password. Bypass any Identity Provider (IdP) routing rules if necessary.
- Navigate to the Okta Admin Console in the Spoke organization and go to Reports > System Log.
- Verify that Okta successfully triggers a Push Password Update for the Org2Org application.
- Instruct the user to attempt to sign in to the Hub organization using the synchronized Okta password from the Spoke organization.
