Okta AWS CLI Fails With "The application's assurance requirements are not met by the 'subject_token'." Error
Last Updated:
Overview
When running the okta-aws-cli utility, Okta generates an error if the Amazon Web Services (AWS) Security Assertion Markup Language (SAML) Federation Application authentication policy is more restrictive than the OpenID Connect (OIDC) Application authentication policy. Configure both applications to use the same authentication policy without requiring device management or frequent re-authentication to resolve the issue. The okta-aws-cli console displays the following error after a browser authentication:
Error: fetching SSO web token received API response "400 Bad Request", error: "invalid_grant", description: "The application's assurance requirements are not met by the 'subject_token'."
Applies To
- Okta Identity Engine (OIE)
- okta-aws-cli
- Okta AWS Federation Application (SAML)
Cause
The AWS SAML Federation Application authentication policy is more restrictive than the OIDC Application authentication policy. The AWS SAML Federation Application authentication policy requires a managed device or requires a re-authentication frequency on every sign-in attempt.
Solution
What are the steps to configure the authentication policies and resolve the assurance requirements error?
Configure the AWS SAML Federation Application and the OIDC Application to use the same authentication policy without requiring device management or frequent re-authentication.
- Navigate to Security > Authentication Policies.
- Verify the same policy applies to both the SAML Federation and OIDC applications.
- Edit the applicable policy or rules.
- Verify the Device state is dropdown menu displays Any.
- Verify the Re-authentication frequency is dropdown menu displays Never re-authenticate if the session is active, or displays at least Re-authenticate after 1 Minute.
The following image displays the device state setting with the any value selected.
The following image shows the re-authentication frequency setting with the "never re-authenticate" value selected.
Separate authentication policies apply different device state and re-authentication frequency requirements.
Configure separate policies for the OIDC Application and the AWS SAML Federation Application to apply different device state and re-authentication frequency requirements.
- Configure the OIDC Application policy to require Device state is to equal Registered and Re-authentication frequency is to equal Every sign-in attempt.
- Configure the AWS SAML Federation Application policy to omit management requirements and set the Re-authentication frequency is dropdown menu to Every 1 minute or a larger value.
