<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Access Gateway Single Sign-On Fails in an iframe with a Valid Session

Access Gateway
Okta Classic Engine
Okta Identity Engine

Overview

A Single Sign-On (SSO) failure occurs when a user attempts to authenticate inside an iframe with a valid Okta session. Resolve this issue, caused by blocked third-party cookies in the browser, by allowing third-party cookies. When this issue occurs, Okta populates the login page in the iframe instead of successfully authenticating the user to the application, even when the administrator enables the trusted origin for iframe embedding.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Access Gateway (OAG)
  • Applications with iframes

Cause

The browser blocks third-party cookies. Consequently, the browser does not send existing Okta session cookies with Security Assertion Markup Language (SAML) requests through the iframe.

Solution

How is the iframe authentication failure resolved?

Configure the browser settings to allow third-party cookies.

Related References

Loading
Okta Access Gateway Single Sign-On Fails in an iframe with a Valid Session | Okta Support