This article explains why users are not prompted to set up Multi-Factor Authentication (MFA) upon login after their MFA factors are reset.
- Multi-Factor Authentication (MFA)
- Factor Enrollment Policy
- Okta Classic Engine
The Factor Enrollment rule is configured for the first time a user signs in. Therefore, existing users who have previously logged into Okta will not receive prompts to enroll in MFA.
Please ensure that the Factor Enrollment rule under Security Multifactor Factor Enrollment is set to the first time the user is challenged for MFA.
