Agentless DSSO Enters a Login Loop When Using a Custom URL After an Okta Identity Engine Upgrade
Last Updated:
Overview
After upgrading to the Okta Identity Engine (OIE), Agentless Desktop Single Sign-On (ADSSO) authentication functions correctly on the standard org URL (https://<org>.okta.com), but a self-referencing redirect causes a continuous login loop when ADSSO fails on a custom URL. The login loop persists until the user stops the browser from loading. Resolving this issue requires creating a custom error URL with a help link that guides the user to the default login page.
Applies To
- Okta Identity Engine (OIE)
- Directories
- Agentless Desktop Single Sign-On (ADSSO)
- Custom login URL
Cause
The OIE upgrade creates a self-referencing redirect for the custom login URL. If ADSSO fails, Okta redirects the authentication request back to the custom login URL, which creates a login loop.
Solution
How is the ADSSO login loop resolved?
Navigate to the customizations settings in the Admin Console, edit the access denied error message, and enter a custom error message with a help link pointing to the default login page.
- Navigate to Customizations > Other in the Okta Admin Console.
- Locate the Access denied error message section and click Edit.
- Enter a custom error message along with the help link text and URL.
NOTE: The default login for any Okta org, whether using the standard org URL or a custom URL, is<site>/login/default. - Click Save.
