<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Sign-In Widget Displays Generic "Unable to sign in" Error for Locked Accounts

Okta Identity Engine
SDKs & Libraries

Overview

The Okta Sign-In Widget displays a generic error message for locked accounts when the password policy suppresses lockout failures or when User Enumeration Prevention (UEP) for recovery is enabled. Administrators resolve this by disabling UEP for recovery and enabling the lockout failure display setting in the password policy. When an account locks due to exceeding the maximum failed login attempts, the user receives the following error message during authentication:

 

Unable to sign in

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Sign-In Widget (Hosted and Embedded)
  • User Enumeration Prevention (UEP)
  • Password Policy
  • Authenticators

Cause

Okta suppresses explicit lockout notices to prevent attackers from confirming account existence when the password policy disables the lockout failure display setting. Additionally, Okta evaluates whether the transaction qualifies for a self-service account unlock when an account locks during sign-in. Because Okta categorizes account unlocks as a recovery mechanism, Okta evaluates the request against the recovery UEP policy. If administrators enable UEP for recovery, it supersedes the password policy lockout display settings. Okta suppresses the specific lockout error and returns a generic failure to prevent attackers from discovering the account status or enrolled recovery factors.

Solution

What steps are required to disable User Enumeration Prevention for recovery?

Navigate to the general security settings and clear the recovery checkbox to disable the feature, as described in the following steps:

 

NOTE: Disabling UEP for recovery allows the Okta Sign-In Widget to display the account status and available self-service recovery options. Evaluate the organizational security posture regarding user enumeration before modifying this setting.

 

  1. Navigate to Security and select General.
  2. Scroll to the User Enumeration Prevention section.
  3. Clear the Recovery checkbox.

User Enumeration Prevention

  1. Select Save.

 

What steps are required to enable the "Show lockout failures" option for the password policy?

Navigate to the authenticators menu to edit the password policy and enable the lockout failure display setting, as described in the following steps:

  1. Navigate to Security and select Authenticators.
  2. Select the Password authenticator and select Actions, followed by Edit.
  3. Select the policy assigned to the affected users and select Edit.
  4. Select the Show lockout failures checkbox in the Lock out section.

Password Security

  1. Select Update Policy to save the changes.
Loading
Okta Sign-In Widget Displays Generic "Unable to sign in" Error for Locked Accounts | Okta Support