Newly Created Okta-Sourced Account Status Shows Password Expired and User Is Now in One-Time Password Mode
Last Updated:
Overview
A newly created Okta-sourced account shows the status of "Password expired. User is now in one-time password mode". This status occurs when the administrator selects the option that requires the user to change the password on first login. The user can resolve this status by logging in with the temporary password and creating a new password.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta-Sourced Users
Cause
The administrator selects the User must change password on first login option, requiring the user to change the password on the first login during account creation. This selection sets the initial password to be temporary, causing it to expire immediately.
Solution
Why does a newly created Okta-sourced account show a password expired status?
The user must change the password on the first login, and the password set by the administrator is simultaneously used.
When the administrator selects the option requiring a password change on the first login, Okta considers the initial password temporary. This temporary password expires immediately, triggering the expired password status. When a user account shows an Expired Password status, it means they will be forced to change their password on the next successful login to Okta.
