<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008Gj2ktSABOkta Classic EngineLifecycle ManagementAnswered2024-04-15T11:57:46.000Z2018-08-30T21:58:32.000Z2018-09-04T18:34:57.000Z

zbb3v (zbb3v) asked a question.

E0000064 expected but getting E0000004

After a password has expired, when using the sign in widget, the authn endpoint returns the error code E0000004 when E0000064 is expected so we can handle the expired password workflow.

 

Is this a bug? Is this expected behavior?


  • ion.nits1.533124184742478E12 (Vendor Management)

    Hi Scott,

     

    The HTTP Error Code 401 and "Authentication failed" message will always be returned for requests with invalid credentials, locked out accounts or access denied by a sign-on policy. This is expected, and is in place for security reasons. There is not an option today to modify the error code and present what is incorrect as this is made to stop brute force attempts. Okta will provide the least amount of information as possible for authentication failures, so that if someone is trying to hack into user account, they should not get much information as why authentication is failing or they should not know what state user is in.

     

    Ion Nits

    Okta Global Customer Care

    Expand Post
    Selected as Best
  • ion.nits1.533124184742478E12 (Vendor Management)

    Hi Scott,

     

    The HTTP Error Code 401 and "Authentication failed" message will always be returned for requests with invalid credentials, locked out accounts or access denied by a sign-on policy. This is expected, and is in place for security reasons. There is not an option today to modify the error code and present what is incorrect as this is made to stop brute force attempts. Okta will provide the least amount of information as possible for authentication failures, so that if someone is trying to hack into user account, they should not get much information as why authentication is failing or they should not know what state user is in.

     

    Ion Nits

    Okta Global Customer Care

    Expand Post
    Selected as Best
This question is closed.
Loading
E0000064 expected but getting E0000004