<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
User Receives "403 Access Forbidden" Error When Logging In
Okta Classic Engine
Okta Identity Engine
ThreatInsight
Network Zone
Overview

This article clarifies why a user receives the following error when attempting to access Okta:

403 Access Forbidden

 

Okta 403 Access Forbidden Image

Applies To
  • Authentication Policy
  • Sign-on Policy
  • Network Zone
  • ThreatInsight
  • State Token
Cause

The 403 Access Forbidden error indicates that the user cannot access the page. This error can occur for several reasons:

  • The user does not meet the Sign-on Policy requirements that apply to them.

  • The user attempts to access the tenant from an Internet Protocol (IP) address that a Network Zone blocks.

  • Access is blocked by ThreatInsight.

  • The user accesses the integrated application, opens a new browser tab, stays with the new tab for more than 5 minutes, and then returns to the original browser tab to access the integrated application. The current State Token expiration time is 5 minutes.

Solution

Perform the following steps to resolve the problem:

  1. Review the Authentication/Sign-on Policies that apply to the user and ensure that the user meets the requirements to be allowed access.

  2. Review the configured Network Zones to ensure that the user's IP address is not being blocked.

  3. Review "403 Access Forbidden" when Navigating to the Login Page.

NOTE: The current State Token expiration time is 5 minutes.

Related References

Loading
User Receives "403 Access Forbidden" Error When Logging In