<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Jamf Connect Authentication Fails at Certain Locations

Okta Identity Engine
API Access Management

Overview

At specific locations, logging into Okta via Jamf Connect fails with:

"Login Authentication failed, reason: Authentication failed, Try signing in again."

Okta System Logs do not indicate any issues.

Applies To

  • Okta Identity Engine
  • Jamf Connect
  • Jamf Connect Configured to use OIE Authentication Method
  • DSSO or ADSSO

Cause

There can be a number of reasons why authenticating with Jamf Connect can fail with Authentication failed, Try signing in again.


If this error is observed for users only in specific locations, and those locations are not part of a network deny zone, then this issue could be related to DSSO/ADSSO settings. Active Directory Desktop Single Sign On settings most often is enabled for specific locations, either office or corporate VPNs.

 

When DSSO is enabled, and Jamf Connect is configured for OIE login mode (Interact code flow), Okta will respond with a login attempt with a URL to start the DSSO login flow.


As of Jamf Connect v2.35.0, this will result in:

Authentication failed, Try signing in again.


Okta system logs will show as Success since this is not an error condition on the Okta side.

 

Solution

Depending on the circumstance, users should either not attempt to use Jamf at these locations, or the Jamf Connect routing rule can be updated in a way so it makes exceptions to specific IPs, Applications, or Platforms.

 

This routing rule is automatically generated when DSSO is enabled.

 

To edit:

  • Navigate to Security > Identity Providers > Routing Rules.
  • The rule name is "Default Route to AgentlessDSSO". 
Loading
Okta Support - Jamf Connect Authentication Fails at Certain Locations