
NavjotS.39419 (Customer) asked a question.
Currently i am facing an issue where i am already logged-in to my okta dashboard and one of my app's assertion is expired. In this case when i try to open my app from dashboard i get an exception of "authentication statement is too old". I have to logout from okta and login back to have access to my app. My question is why i cannot have access to my app when i am already logged in to my app ? Any suggestions

Hi @NavjotS.39419 (Customer) , Thank you for reaching out to the Okta Community!
You haven't specified what app is involved here, but based on what I've been able to research, it seems to be something similar to the following:
https://stackoverflow.com/questions/30528636/idp-initiated-saml-login-error-authentication-statement-is-too-old-to-be-used/30543585#30543585
Looking at whatever info I have internally, I can say that there's nothing much that can be done from the Okta side as the typical SAML app configuration is either hardcoded or non-existent when it comes to sessions. Sessions are defined on the Service Provider (app) side.
I did find some reference to the "Force Auth" function (a.k.a "Honor Force Authentication" ), that may prevent the failure but is not ideal for the end-user experience.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
The October issue of the Okta Community is here and packed with tips on certification, how to earn badges, and new releases. Let us help you stay connected.