Jamf Connect Authentication Fails at Certain Locations
Last Updated:
Overview
At specific locations, logging into Okta via Jamf Connect fails with:
"Login Authentication failed, reason: Authentication failed, Try signing in again."
Okta System Logs do not indicate any issues.
Applies To
- Okta Identity Engine
- Jamf Connect
- Jamf Connect Configured to use OIE Authentication Method
- DSSO or ADSSO
Cause
There can be a number of reasons why authenticating with Jamf Connect can fail with Authentication failed, Try signing in again.
If this error is observed for users only in specific locations, and those locations are not part of a network deny zone, then this issue could be related to DSSO/ADSSO settings. Active Directory Desktop Single Sign On settings most often is enabled for specific locations, either office or corporate VPNs.
When DSSO is enabled, and Jamf Connect is configured for OIE login mode (Interact code flow), Okta will respond with a login attempt with a URL to start the DSSO login flow.
As of Jamf Connect v2.35.0, this will result in:
Authentication failed, Try signing in again.
Okta system logs will show as Success since this is not an error condition on the Okta side.
Solution
Depending on the circumstance, users should either not attempt to use Jamf at these locations, or the Jamf Connect routing rule can be updated in a way so it makes exceptions to specific IPs, Applications, or Platforms.
This routing rule is automatically generated when DSSO is enabled.
To edit:
- Navigate to Security > Identity Providers > Routing Rules.
- The rule name is "Default Route to AgentlessDSSO".
