<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Using Short Match Login for Okta User Authentication

Administration
Okta Classic Engine
Okta Identity Engine

Overview

Okta allows users to authenticate using either the full username or a short match login, which omits the domain portion of the username. However, an error occurs if multiple users share the same short username across different domains and attempt to use the short match login feature.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • User Authentication

Solution

How does short match login function in Okta?

A user authenticates into Okta using the full username or a short match login. The short match login allows authentication with just the username prefix, removing the domain suffix (for example, using <username> instead of <username@exampledomain.com>).

This feature includes a specific limitation regarding duplicate prefixes. If two users share the same username prefix but use different domains (e.g., <username@exampledomain1.com> and <username@exampledomain2.com>), Okta generates an error message when either user attempts a short match login.

Review the following image for an example of the error message that Okta generates during a duplicate short match login attempt.

Test user

Loading
Okta Support - Using Short Match Login for Okta User Authentication