getsentry / getsentry/sentry

Sentry Prompts Okta SSO Users for unconfigured 2FA

Open
#57,931 4 comments 1 reaction 1 assignee Claimed by @nhsiehgit View on GitHub
Bug Product Area: Settings - Members
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
1d 5h
Merged PRs (30d)
624

Description

### Environment

SaaS (https://sentry.io/)

### Steps to Reproduce

**Description:**
Following a domain change in Okta, users with new email domains are prompted for 2FA during login, even though the organization lacks 2FA configuration, resulting in the users being unable to accept the invite and login.

The customer confirmed the following steps:
- Okta is set up for the new email domains.
- The "Deactivate Users" flag is active.
- They deleted and reconfigured the SSO app in Okta and Sentry.
- Users initiated new sessions and logged out of Sentry before accepting invites.
- No 2FA is enabled in their Okta instance.

Support ticket with SAML tracer & additional org details: https://sentry.zendesk.com/agent/tickets/102751

### Expected Result

Users with new email domains should be able to accept invitations and log in without being prompted for 2FA, given that the organization does not have 2FA configured.

### Actual Result

Users with new email domains are unexpectedly prompted for 2FA during the login process, despite the organization's 2FA configuration being absent.

### Product Area

Settings - Members

### Link

_No response_

### DSN

_No response_

### Version

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.