This article outlines the procedure for implementing a mandatory Security Question enrollment process for new users upon initial authentication. The procedure can be executed even if the Security Question enrollment is set to Disabled in the Factor Enrollment Policy by utilizing the Password Policy.
- Okta Identity Engine (OIE)
- Password Policy
- Self-service account recovery
- Multi-factor Authentication (MFA)
- Log in to the Okta Admin Console.
- Go to the Security tab, and then click on the Authenticators tab.
- Click Actions and then Edit on the Password authenticator.
- Add New Password Policy or edit an existing policy that should apply the security question.
- Add a Rule to the policy.
- In the Additional Verification is section, select the Only Security Question option.
