
MichaelW.03509 (Customer) asked a question.
Hi I have Azure AD as the IDP for Okta. First login attempt JIT creates the user in Okta but user is unable to login and logs show PASSWORD_BASED_LOGIN_DISALLOWED. Account credentials in Azure AD are correct and verified. Logins from Azure's SAML Test login link work and correctly brings up the user Apps Portal in Okta. Any ideas how to fix this??? Thanks!

Thank you for reaching out to Okta Customer Support.
The user account is created via Just-in-Time Provisioning (JIT) before credentials are set on the IDP side.
Performing a password reset for the account from the IDP end should restore the user's access.
If not, feel free to open an ticket with our support team for further investigation.