Troubleshooting
Problem
After attempting to create a new schedule, the user will get prompted with an error message saying: AAA-AUT-0013 The user is already authenticated in all available namespaces.
Symptom
Issue specific to OKTA or any Open ID Authentication Provider namespaces.
If the customer is using an Identity Provider that does not support password grant, then using the OKTA namespace type will not work for scheduling.
Resolving The Problem
Use a "Generic" OIDC namespace type. For scheduling, they should change the setting from credentials to id_token only.
However, it's worth mentioning that Cognos Analytics will not verify that the user is still active in the Identity Provider. Also, if their IdP supports groups, CA will not refresh the user's group memberships.
Was this topic helpful?
Document Information
Modified date:
06 June 2023
UID
ibm10733691