
zbb3v (zbb3v) asked a question.
After a password has expired, when using the sign in widget, the authn endpoint returns the error code E0000004 when E0000064 is expected so we can handle the expired password workflow.
Is this a bug? Is this expected behavior?

Hi Scott,
The HTTP Error Code 401 and "Authentication failed" message will always be returned for requests with invalid credentials, locked out accounts or access denied by a sign-on policy. This is expected, and is in place for security reasons. There is not an option today to modify the error code and present what is incorrect as this is made to stop brute force attempts. Okta will provide the least amount of information as possible for authentication failures, so that if someone is trying to hack into user account, they should not get much information as why authentication is failing or they should not know what state user is in.
Ion Nits
Okta Global Customer Care