Common Okta Login Failures and Troubleshooting Steps
Last Updated:
Overview
Users encounter various Okta authentication errors during login attempts due to incorrect credentials, expired sessions, or network issues. Review the common error codes, descriptions, and basic troubleshooting steps to resolve these login failures.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Login Failures
- Authentication Errors
Solution
What are the common Okta login failures and troubleshooting steps?
Review the following table to identify common Okta login errors, their descriptions, and the basic troubleshooting steps required to resolve them.
|
Error
|
Error Code
|
Description
|
Basic troubleshooting steps
|
|---|---|---|---|
|
INVALID_CREDENTIALS
|
E0000004
|
The provided credentials are incorrect.
|
Ensure that the username and password are correct. Copying the values sometimes captures invalid characters. Enter the credentials manually.
|
|
LOCKED_OUT
|
E0000069
|
The user exceeds the allowed number of failed login attempts (typically 3-5 attempts) or does not satisfy the Multi-Factor Authentication (MFA) requirements.
|
Review the following article for situations in which users lock themselves out of their accounts by failing to enter the password correctly or to satisfy the required MFA: Failed Login Attempts Allowed Before an Account Is Locked Out and How to Unlock It.
|
|
PASSWORD_BASED_LOGIN_DISALLOWED
|
-
|
Okta does not permit password login for this user.
|
To resolve password reset issues for users created via social login or an external identity provider, administrators must perform the reset on the social login side. For more details, review Resolve Password Reset Issues for Users Created via Social Logins/External IDP in Okta.
|
|
UNKNOWN_USER
|
E0000007
|
Okta cannot find the user attempting to authenticate.
|
Verify that the username is correct and that the user account exists in Okta. Check for typos or case sensitivity issues.
|
|
VERIFICATION_ERROR
|
-
|
An error occurs during the verification process.
|
- Verify that the username is entered correctly.
- Verify that the user exists in Okta. - In the System Log, expand the event and check the DisplayName and ID fields—an unknown value indicates that the user does not exist. For more details, review Understanding "FAILURE: VERIFICATION_ERROR" in System Log. |
|
GENERAL_NONSUCCESS
|
E0000006
|
A general failure occurs that does not fall into other specific categories.
|
Check the System Log for detailed error messages. Contact a system administrator if the issue persists. For example, when logging in with an external Security Assertion Markup Language (SAML) Identity Provider (IdP) fails due to this error, detailed error messages appear in the System Log. For more information, review “400: Bad Request Error Code: GENERAL_NONSUCCESS” Received when Attempting Login with SAML IDP.
|
|
MFA_REQUIRED
|
E0000047
|
The user does not provide the required MFA.
|
Complete the MFA setup process. Ensure access to a registered MFA device. Review the following documentation for more details: Transaction state.
|
|
SESSION_EXPIRED
|
-
|
The user session times out and requires re-authentication.
|
Sign in again to start a new session. Okta does not generate log events for non-explicit user logouts. If a user session expires due to either idle time or max session lifetime, Okta does not generate an event in the System Log. Okta only generates an event if the user explicitly logs out by selecting Sign out or if an admin revokes the user session: Does System Log Show when a User's Session Times Out or Ends.
|
|
INVALID_TOKEN
|
E0000011
|
The provided API token is invalid or expired.
|
Generate a new API token. Ensure the token does not exceed its validity period. Verify that the Okta account used to create the API token is still active. For more information, review Error "HTTP 401 Okta E0000011 Invalid Token provided".
|
|
RATE_LIMIT_EXCEEDED
|
E0000047
|
The user attempts too many logins in a short time period.
|
This error occurs when the API call exceeds the rate limit due to too many requests. For details about authentication and end-user activity rate limits, review the following documentation: Authentication and end-user rate limits.
|
|
NETWORK_CONNECTION_ERROR
|
-
|
Okta cannot establish a connection with the authentication server.
|
A network connection error when signing in to Okta indicates connectivity issues between the device and Okta servers. Check the following areas:
|
|
PASSWORD_EXPIRED
|
-
|
The user password expires and requires a reset.
|
Follow the password reset procedure and create a new password that meets the Okta complexity requirements. Users also see this error when they are in a Password Expired state in Okta and authenticate via an External IdP into Okta. For more details and resolution, review Get Password Expired: 400 Status when Providing Valid Authentication via External IDP.
|
