<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
"Match entire username" Setting Fails to Block AD Short Name Logins
Single Sign-On
Okta Identity Engine
Overview

When the following setting is enabled: "Username match criteria on sign in - Match entire username" in the Okta admin console under Settings > General, the Active Directory (AD) users are still able to log in using firstname.lastname.

Applies To
  • Okta Login
  • Okta Identity Engine (OIE)
  • General Settings
Cause

This happens for AD Users only. Okta created users are not allowed to login using short name when the setting is enabled.

Solution

In the Admin console, change the Okta username format under Provisioning > To Okta to Email Address. Then, logging in with a short name is not allowed for AD users. They must log in using the full email.

Directory integrations

Loading
"Match entire username" Setting Fails to Block AD Short Name Logins