<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

External Identity Provider Authentication Error "FAILURE: User Denied/Rejected"

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

This article explains why authentication fails when using an external Identity Provider (IdP) with the following error:

 

FAILURE: User Denied/Rejected

 

User Denied/Rejected

Applies To

  • Security Assertion Markup Language (SAML) Identity Provider (IdP)

  • Single Sign-On (SSO)

Cause

The error occurs because the external IdP configuration restricts access based on a specific username format. When the system attempts to authenticate a user, if the username does not satisfy the pattern requirements, the authentication request is rejected.

Solution

To resolve this issue, update the RegEx pattern to accommodate the user's username or disable the restriction.

  1. In the Okta Admin Console, navigate to Security > Identity Providers.
  2. Locate the affected external IdP and select Action > Configure Identity Provider.
  3. Scroll to the Only allow usernames that match defined RegEx Pattern setting.

Only allow usernames that match defined RegEx Pattern  

  1. Perform one of the following actions:
    • Clear the checkbox to remove the username restriction.
    • Modify the field to allow the restricted username.
  2. Click on Update Identity Provider to save the configuration.
Loading
Okta Support - External Identity Provider Authentication Error "FAILURE: User Denied/Rejected"