Using the Access Testing Tool with Federation Broker Mode Enabled Applications
Last Updated:
Overview
When running the Access Testing Tool on applications that have Federation Broker Mode enabled, Okta Admins may encounter the following error:
Test an access scenario failed
Access to <application_name> is not allowed. <Username> is not assigned to this application.
Applies To
- Okta Identity Engine (OIE)
- Access Testing Tool
- Federation Broker Mode
Cause
The Access Testing Tool expects the user to be assigned to the application while testing. If the user is not explicitly assigned to the tested application, an error will occur.
Solution
- In the Admin Dashboard, navigate to the application, disable Federation Broker Mode, and save the change.
- Assign the user to the application under the Assignments tab of the application.
- Re-enable Federation Broker Mode.
- Run the Access Testing Tool again.
