Accessing an OIDC Application in Okta Bypasses the "Access Denied" Error Configured in Customizations
Last Updated:
Overview
When a Global Session Policy denies access to an OpenID Connect (OIDC) application, Okta redirects the authentication flow to a server error instead of displaying the custom error message on the Sign-In Widget (SIW). Administrators must configure a custom error page on a Custom Domain to display the correct message. When attempting to access an OIDC application, a brief glitch occurs where the Access Denied error message appears for a few seconds before Okta redirects to a server error page.
Applies To
- Okta Identity Engine (OIE)
- Customizations
- OpenID Connect (OIDC)
- Security Assertion Markup Language (SAML)
Cause
Because the Global Session Policy denies access, Okta redirects the authentication flow to a server error rather than displaying the custom error message on the SIW. This behavior differs from Security Assertion Markup Language (SAML) applications, which do not redirect and instead display the Access Denied error message directly on the SIW.
Solution
How do administrators configure the custom error message for OpenID Connect applications?
Configure the custom error message on a Custom Domain. Configuring the error message by navigating to Customizations > Other does not apply to OIDC applications.
