<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Permission Error Occurs During Windows Autopilot Integration for Office 365

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

When a user initiates the Windows Autopilot integration for Microsoft Office 365, an authentication error occurs after entering the username. This happens because the Autopilot authentication policy rule for Microsoft Office 365 is missing or lacks the correct configuration. Configuring the appropriate sign-on policy rule in the Okta Admin Console resolves the issue. When this error occurs, Okta displays the following message:

 

You do not have permission to perform the requested action

 

Additionally, the System Log records the following event:

 

Evaluation of sign-on policy DENY

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Windows Autopilot
  • Microsoft Office 365

Cause

The Autopilot authentication policy rule for Microsoft Office 365 is missing or lacks the correct configuration.

Solution

How is the Windows Autopilot sign-on policy rule configured?

Navigate to the Microsoft Office 365 application in the Okta Admin Console and add a new sign-on policy rule for the Windows Autopilot client.

  1. In the Okta Admin Console, navigate to the Microsoft Office 365 application and select the Sign On tab.
  2. Scroll to the Sign On Policy section and click Add Rule.
  3. Enter a name for the rule in the Rule Name field.
  4. Configure the appropriate IF conditions for users and devices.
  5. In the Client section, select One of the following clients from the dropdown menu, and then select Windows Autopilot.
  6. In the Then section, select Access is Allowed after successful authentication.
  7. Select any of the 2 factor types from the user authentication requirements dropdown menu.
  8. Configure the appropriate factor conditions and re-authentication frequency.
  9. Click Save.
  10. Adjust the priority level for the new Autopilot sign-on policy rule in the Sign On Policy section.

 

Related References

Loading
Okta Support - Okta Permission Error Occurs During Windows Autopilot Integration for Office 365