<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Configure Policies for Specific Okta Groups to Authenticate with a Particular Factor
Multi-Factor Authentication
Okta Identity Engine
Overview

For users in an Okta group assigned to an application, a Factor Enrollment Policy, a Global Session Policy, and an Authentication Policy must be configured specifically for that group to prompt users for a specific factor when authenticating to an application. The instructions are provided below.

Applies To
  • Okta Identity Engine (OIE)
  • Multi-Factor Authentication (MFA)
  • Authentication Policies
Solution
  1. Create a Factor Enrollment Policy and assign it to the group.
  2. Set the factor for that group's users to authenticate with as Required (for example, FIDO2(WebAuthn)) and add a Rule.
    policies 

  3. Add a Global Session Policy and assign it to the group.
    Global session policy 

  4. Add a rule to the Global Session Policy and set Establish the user session with to Any factor used to meet the Authentication Policy requirements, and Multifactor authentication (MFA) is Not Required.
    Edit rule 

  5. Create an Authentication Policy and add a rule.

  6. Set AND User must authenticate with Any 1 factor type / IdP.

    • Your org's authenticators that satisfy this requirement will be shown in the box below.
      factor 

 

As Password and FIDO2 (WebAuthn) security methods are set to require, users can choose either factor when signing in.

Okta verify 


Related References

Loading
How to Configure Policies for Specific Okta Groups to Authenticate with a Particular Factor