"The user's password is expired" Error Occurs in Okta Org2Org Hub and Spoke Configuration
Last Updated:
Overview
In an Okta Org2Org configuration where the Spoke tenant authenticates Hub users, the following error occurs if the Hub tenant contains a password expiration policy:
The user's password is expired.
Resolve this issue by removing the password expiration policy on the Hub side.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Org2Org
- Hub and Spoke Architecture
- Password Policy
Cause
The Hub Okta tenant contains a password policy configured with a password expiration day. Because the Spoke Okta tenant authenticates the users, the Hub tenant expiration policy conflicts and generates the error.
Solution
How is the "The user's password is expired." error resolved in an Org2Org configuration?
Prevent the error by disabling the password expiration policy in the Hub Okta Admin Console.
- Sign in to the Hub Okta Admin Console.
- Navigate to the password policy settings.
- Remove or disable any password expiration day configurations.
- Manage password expiration exclusively on the Spoke Okta tenant.
