<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Application Sign-On Policy Risk Level Denies User Access

Okta Classic Engine
Okta Identity Engine
Administration

Overview

This article addresses an issue where a user is denied access to an application. Although the user has the same configuration as other users who can access the application, they are blocked by an Application Sign-On Policy that evaluates their risk level.

Applies To

  • Application Sign-On Policy

Cause

The user is assigned a high risk level because the user has no successful authentication history in the organization. The Application Sign-On Policy contains a rule that grants access based on a password-only factor for users with a low risk level.

Because the user is identified as high risk, they are not evaluated against the intended password-only rule. Instead, they are evaluated against a subsequent, stricter rule that requires a password plus an additional authentication factor. The user is not enrolled in a second factor and is, therefore, denied access.

Solution

  1. Temporarily modify the Application Sign-On Policy to allow the user to authenticate successfully. This can be done by adding a temporary rule that specifically grants access to the user for their initial sign-in.

  2. Instruct the user to sign in. A successful sign-in creates an authentication history.

  3. Once a successful authentication event is recorded, the user's risk level is recalculated and changes from High to Low.

  4. Remove the temporary rule from the Application Sign-On Policy. The user will now be correctly evaluated by the intended policy rule for low-risk users.

 

Related References

Loading
Application Sign-On Policy Risk Level Denies User Access | Okta Support