<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z000078ew3hCAAOkta Classic EngineSingle Sign-OnAnswered2025-03-30T09:12:55.000Z2021-08-30T22:43:19.000Z2021-09-22T15:52:32.000Z

6mpzc (6mpzc) asked a question.

OKTA to AWS SAML Error - Invalid MFA credentials

Image is not available

Hello OKTA Pros - 

 

So I am new to OKTA and have been tasked with enabling SAML. Wondering if anyone on here has experienced the following error with AWS configured:

 

Your MFA credentials were incorrect. Please check your device and try again.

Request ID: 0123d7fc-e2a5-46fa-a523-dee3e94811ea

Time: Mon, 30 Aug 2021 20:48:31 GMT

 

I am Changing between AWS SSO and Okta as the external identity provider (IdP).

 

The section I am not clear on is when do I turn on the idp, since there is a new section where you can create idp users and groups located at https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source-idp.html

 

According to OKTA - The SAML protocol does not provide a way to query the IdP to learn about users and groups. Therefore, you must make AWS SSO aware of those users and groups by provisioning them into AWS SSO.

 

Do we need to know how to use the roles under AWS IAM instead of the OKTA SSO section?

 

Or am I missing something all together?

 

Thanks GANG in advance!

 

-RoDevia

 


  • Hello @6mpzc (6mpzc)​ 

     

    I noticed you have an open case on this issue. Were they able to help you with this?

     

    Regards,

     

    Natalia

    Okta Inc.

    Expand Post
  • 6mpzc (6mpzc)

    Hello - Yes - I still need help with support on my ticket.

  • w8g9r (w8g9r)

    any update on this? i have encountered the same issue

  • gbmqw (gbmqw)

    Okta team,

    I am new to OKTA and encountered the same issue

     

    Invalid MFA credentials

    Your MFA credentials were incorrect. Please check your device and try again.

    Request ID: 59581c7b-897c-4182-982c-b6f03a0e4453

    Time: Wed, 22 Sep 2021 14:07:49 GMT

    Expand Post
  • w8g9r (w8g9r)

    a new token in aws sso had to be generated

This question is closed.
Loading
OKTA to AWS SAML Error - Invalid MFA credentials