Outage Status Now

Guides / Okta SSO not working: outage, MFA, or account lockout?

Updated 3 Oct 2026

Okta SSO not working: outage, MFA, or account lockout?

Tile page dead, one app failing, or MFA that never arrives — three different tickets that all get written up as 'Okta is down'.

Nobody writes "my MFA push did not arrive". They write "Okta is down" or "SSO is broken". Those words hide three faults that want three different responses.

1. The Okta org URL itself does not load

Try https://yourorg.okta.com from a phone off the office Wi-Fi. If it fails everywhere, check the Okta status page. Okta publishes by cell. An APAC cell incident will not look like a US outage. Preview orgs are a different cell again.

Okta's machine-readable feed is unreliable — their Statuspage API returns 401 and the Atom feed has gone stale for long stretches. If we say status unavailable, open status.okta.com yourself. Do not invent a green light.

2. Okta loads, one app fails

That is the app's SAML/OIDC config. Expired signing certificate, ACS URL someone "updated", or a SCIM user who was deactivated. It is not an Okta outage. It is also not Entra unless the app actually bounces to login.microsoftonline.com.

3. Password works, MFA does not

Push notifications, SMS, and number matching fail independently of the directory. Check the factor, the device, and whether the user is in a hard lockout. A break-glass admin account that does not share the same MFA provider is how you still get in to fix it.

Upstream

Okta runs on AWS. A wide AWS event can coincide with Okta being sad. Wait for Okta to post before you start migrating apps to Entra in a Friday afternoon panic.

Related status pages

Still broken? Check another tool