Unable to disable SSO bypass URL http://<iiq server>/spt/login.jsf?prompt=true

Which IIQ version are you inquiring about?

IIQ 8.4

Unable to disable SSO bypass URL http:///spt/login.jsf?prompt=true

We are planning to implement SSO and gone through System configuration guide.
We found that below URL bypasses SSO login


We have users who might have bookmarked above URL, if, they would access IIQ on above URL then SSO login would be bypassed.

We don’t want to have that URL bypassing SSO login page.

We would like to disable above URL or redirect to https://<IIQ_HOST>:8443/identityiq/login.js even a user is hitting https://<IIQ_HOST>:8443/identityiq/login.jsf?prompt=true

Tried KB article - Support Articles - [IdentityIQ] How to disable URL - /login.jsf?prompt=true - Customer Support

but no luck.

Made below changes in web.xml as suggested but no luck.

pageAuthenticationFilter sailpoint.web.PageAuthenticationFilter loginUrl /login.jsf mobileLoginUrl /ui/login.jsf promptLoginUrl /login.jsf promptMobileLoginUrl /ui/login.jsf

Question :

  • How can we stop SailPoint to not bypass SSO login even user is hitting https://<IIQ_HOST>:8443/identityiq/login.jsf?prompt=true?

Made below changes in web.xml as suggested but no luck.

        <param-name>promptMobileLoginUrl</par`Preformatted text`am-name>

Share your complete web.xml with which you tried this

web.xml (42.3 KB)

Please see uploaded web.xml

@rsingh7 your configuration looks good. Hoping you deployed on all boxes. let me see if i found some more details.

If you specifically want to restrict access when prompt=true is passed as a parameter, consider implementing a URL filter. A custom filter can intercept requests to check for the prompt=true parameter and restrict access accordingly.

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import java.io.IOException;
public class RestrictPromptFilter implements Filter {
   public void init(FilterConfig filterConfig) throws ServletException {
   public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
           throws IOException, ServletException {
       HttpServletRequest httpRequest = (HttpServletRequest) request;
       String prompt = httpRequest.getParameter("prompt");
       if ("true".equals(prompt)) {
           request.getRequestDispatcher("/access-denied.jsp").forward(request, response);
       chain.doFilter(request, response);
   public void destroy() {

add this in web.xml


Thanks for sharing suggestions!