Okta Bypasses the Username Page During Federated Authentication from Microsoft
Last Updated:
Overview
When a federated user authenticates via Microsoft Office 365, Okta redirects the user directly to the Okta password entry page and bypasses the Okta username page. This behavior occurs because the Okta Identity Engine release 2025.05.1 automatically processes the username from the Microsoft session to resolve routing rule issues. Contact Okta Support to enable a feature that ignores the incoming login hint and restores the username entry screen.
Applies To
- Okta Identity Engine (OIE)
- Microsoft Office 365
- Login Hint
- Service Provider (SP) Flow
Cause
Okta Identity Engine release 2025.05.1 introduces this behavior to resolve an issue where attribute-based Identity Provider (IdP) routing rules fail to function correctly and to correct an inconsistency in the WS-Federation (WS-Fed) flow. Previously, Okta required users to re-enter the username on the Okta login page to evaluate routing rules, ignoring the login_hint that Microsoft provides. The updated behavior correctly and automatically processes the username from Microsoft, advancing the user directly to the password page.
Solution
How is the username page bypass resolved?
Restore the username entry screen by contacting Okta Support and requesting a feature enablement.
Contact Okta Support and reference this article to request the feature enablement. When Okta Support enables the feature, Okta ignores the incoming login_hint from Microsoft. Consequently, Okta presents the standard login page with a blank username field, allowing the user to enter credentials manually.
