<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Agentless DSSO Enters a Login Loop When Using a Custom URL After an Okta Identity Engine Upgrade

Directories
Okta Identity Engine

Overview

After upgrading to the Okta Identity Engine (OIE), Agentless Desktop Single Sign-On (ADSSO) authentication functions correctly on the standard org URL (https://<org>.okta.com), but a self-referencing redirect causes a continuous login loop when ADSSO fails on a custom URL. The login loop persists until the user stops the browser from loading. Resolving this issue requires creating a custom error URL with a help link that guides the user to the default login page.

Applies To

  • Okta Identity Engine (OIE)
  • Directories
  • Agentless Desktop Single Sign-On (ADSSO)
  • Custom login URL

Cause

The OIE upgrade creates a self-referencing redirect for the custom login URL. If ADSSO fails, Okta redirects the authentication request back to the custom login URL, which creates a login loop.

Solution

How is the ADSSO login loop resolved?

Navigate to the customizations settings in the Admin Console, edit the access denied error message, and enter a custom error message with a help link pointing to the default login page.

  1. Navigate to Customizations > Other in the Okta Admin Console.
  2. Locate the Access denied error message section and click Edit.
  3. Enter a custom error message along with the help link text and URL.
    NOTE: The default login for any Okta org, whether using the standard org URL or a custom URL, is <site>/login/default.
    Custom Error
  4. Click Save.
    Error
Loading
Okta Support - Agentless DSSO Enters a Login Loop When Using a Custom URL After an Okta Identity Engine Upgrade