<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Verifying Authentication Policy after Okta Identity Engine Upgrade
Okta Identity Engine
Administration
Overview

This article aims to explain how to verify Authentication Policies after the Okta Identity Engine (OIE) upgrade.

  • If any applications are added to the authentication policy named "Any Two Factors", please verify that the actual rules in the policy meet the application security assurance levels that should be implied.
Applies To
  • Okta Identity Engine (OIE)
  • After OIE Migration 
  • Authentication Policy 
Solution
  1. Log in to the Okta Admin Console.

  2. Go to Security > click on Authentication Policies > look for a policy that says Any two factors.

Any two factors policy

  1. Once the Any Two Factors policy opens, the requirements to gain access will be displayed. 

requirements to gain access

 

 

How to rename a policy to Password Only policy:

  1. Log in to the Okta Admin Console.

  2. Go to Security > click on Authentication Policies > look for a policy that says Any two factors.

    User-added image

  3. Once on the Any Two Factors Policy settings page, an Actions dropdown list will be visible. From there, select Edit name and description.

Actions button

  1. A pop-up window will appear, allowing the policy to be renamed and the description to be changed. Once done, click Save.

               Edit Authentication Policy 

 

 

How to modify the Any two factors rule to ask for any two factors:

  1. Log in to the Okta Admin Console.

  2. Navigate to Security > click on Authentication Policies > look for a policy that says Any two factors.                               

             Any two factors policy 

  1. On the Any two factors policy settings, a Catch-all-Rule is added by default. To the right of that, there is an Actions button with a drop-down.

  2. Click Edit.

Actions menu

  1. In the new pop-up window, scroll down to the heading THEN and look for the statement AND user must authenticate with. A drop-down list will currently be set on Password or Password/IDP.                                                                                                                                                         Policy Settings 

  2. Click on the drop-down and select the option Any 2 factor types.

           Policy Settings                                                                             

  1. Once Any 2 factor types is selected, additional choices will be visible. Set up the policy based on the application/company security policies.

Policy Settings               ​​​​​​​

  1. Once the policy rule matches the needed criteria, click on Save.​​                                                                                                                    

​​​​​​​Policy Settings

Related References

Loading
Verifying Authentication Policy after Okta Identity Engine Upgrade