<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Enabling Security Question as a Second Authenticator in Okta Identity Engine: Best Practices and Implementation Steps
Multi-Factor Authentication
Okta Identity Engine
Overview

In Okta Identity Engine (OIE), enabling Security Question as a second authenticator requires specific configuration settings. If the Global Session Policy is set to Establish the user session with: Any factor used to meet the Authentication Policy requirements, the Security Question option will not be available to the end-user when prompted to authenticate in the Verify it's you with a security method window. This article explores best practices for enabling Security Question as a secondary authenticator in OIE and outlines implementation steps to ensure a smooth process.

 Verify it's you with a security method window  

Applies To
  • Okta Identity Engine (OIE)
  • Global Session Policy
  • Authentication Policies
  • Multi-Factor Authentication (MFA)
  • Security Question
Solution

Check out this video for more information.

To enable Security Question as a second authenticator in OIE, the Global Session Policy must be set to Establish the user session with: A password. Additionally, ensure that the Security Question is set for both Authentication and Recovery purposes. Subsequently, verify that the Authentication Policy is configured to enable the use of Security Question in the authentication process.

Authenticators

Global Session Policy 
 
 

To enable Security Question as a second authenticator in OIE, follow these steps:

  1. Log in to the Okta Admin Console.
  2. Go to Security and select Global Session Policy.
  3. Click Add Policy

    Add policy 

  1. Provide a title and description for the policy, and include a rule.
  2. Under Establish the user session with, select A password.
     Establish user session with a password 
  3. Click Create rule to apply the policy.
     

Related References

Loading
Enabling Security Question as a Second Authenticator in Okta Identity Engine: Best Practices and Implementation Steps