<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

"The user's password is expired" Error Occurs in Okta Org2Org Hub and Spoke Configuration

Okta Classic Engine
Okta Identity Engine
Administration

Overview

In an Okta Org2Org configuration where the Spoke tenant authenticates Hub users, the following error occurs if the Hub tenant contains a password expiration policy:

 

The user's password is expired.

 

The user's password is expired 

 

Resolve this issue by removing the password expiration policy on the Hub side.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Org2Org
  • Hub and Spoke Architecture
  • Password Policy

Cause

The Hub Okta tenant contains a password policy configured with a password expiration day. Because the Spoke Okta tenant authenticates the users, the Hub tenant expiration policy conflicts and generates the error.

Solution

How is the "The user's password is expired." error resolved in an Org2Org configuration?

Prevent the error by disabling the password expiration policy in the Hub Okta Admin Console.

  1. Sign in to the Hub Okta Admin Console.
  2. Navigate to the password policy settings.
  3. Remove or disable any password expiration day configurations.
  4. Manage password expiration exclusively on the Spoke Okta tenant.
Loading
Okta Support - "The user's password is expired" Error Occurs in Okta Org2Org Hub and Spoke Configuration