<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008dHTsSCAWOkta Classic EngineInsights and ReportingAnswered2025-08-15T09:00:08.000Z2023-01-06T20:12:38.000Z2023-01-09T16:25:45.000Z

0bsfq (0bsfq) asked a question.

What is the meaning of "login_denied" for the reason an authentication failed?

Hi,

 

Every month I audit SSO authentication failure reasons to make sure there are no alarming trends. This month, I am seeing a +10% increase in authentication failures with a reason of "login denied". I cannot seem to find any information or documentation on this, since it seems to be a legacy event type. Can anyone explain the meaning of this reason code?

 

Image is not available


  • Hi @0bsfq (0bsfq)​ , Thank you for reaching out to the Okta Community!

     

    It depends on the context, but this typically happens due to the sign on policies and whether or not the user meets the requirements (ex. IP zone). On the same note, it might be due to ThreathInsight which has the potential to cause "false alarms" in today's context of working from home and varying networks.

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Hi @0bsfq (0bsfq)​ , Thank you for reaching out to the Okta Community!

     

    It depends on the context, but this typically happens due to the sign on policies and whether or not the user meets the requirements (ex. IP zone). On the same note, it might be due to ThreathInsight which has the potential to cause "false alarms" in today's context of working from home and varying networks.

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
    • 0bsfq (0bsfq)

      Hi Mihai,

       

      Thanks for the insight. I will look into ThreatInsight, but on the contrary, we do indeed have sign-on policies that restrict via source IP. This is how we currently force only managed assets to have access to some cloud-based resources, as only managed assets will be able to VPN and tunnel Okta traffic through our data centers. This is most likely the cause.

      Expand Post
  • DonF.81354 (Customer)

    Hi! Thanks for asking your question here. In my experience, and after going back and reviewing a few cases of my own, it appears to be linked in my own case to sign-on policies that were triggered, like denying certain networks (or requiring that they login from say, the company network/vpn).

     

    Have you been able to choose one (perhaps the most recent) and do a deeper dive into their particulars? Is there any conflict with a sign-on policy? Was/is the user able to report on the message they received when attempting to login? What is interesting is that even in my own case, I do not see the processing of a particular policy afterwards.

     

    If you could provide more context on some of your policies or anything like that it may help. Thanks!

    Expand Post
  • 0bsfq (0bsfq)

    Hi Don,

     

    I think it is indeed sign-on policies! Thanks for sharing your experience.

This question is closed.
Loading
What is the meaning of "login_denied" for the reason an authentication failed?