Okta Device Platform Single Sign-On Authentication Fails Due to Account Lockout
Last Updated:
Overview
Authentication failures occur during Okta Device Platform Single Sign-On (SSO) when users repeatedly enter incorrect passwords, triggering the account lockout policy. Administrators must unlock the account and verify that the user enters the correct password to restore access. The Okta System Log displays the following events and outcome reasons:
eventType eq "device.platform_sso.authentication" and outcome.result eq "FAILURE"
User locked out due to multiple invalid password attempts
During the login process, end-users encounter the following error:
We found some errors. Please review the form and make corrections.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Device Platform SSO
Cause
Users repeatedly enter incorrect passwords during Device Platform SSO authentication, which triggers the Okta account lockout policy.
Solution
How is the account lockout resolved for Device Platform Single Sign-On?
Administrators must unlock the affected user account in the Okta Admin Console and verify the user enters the correct password to restore authentication access.
- Navigate to the Okta Admin Console.
- Go to Directory and select People.
- Search for and select the affected user account.
- Select Unlock Account to remove the lockout status.
- Instruct the user to authenticate using the correct password during the Device Platform SSO login process.
