<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Why Can Locked Out Users Log In when Factor Sequencing is Enabled
Okta Classic Engine
MFA
Devices and Mobility
Overview
This article explains why locked-out users are able to log in when Factor Sequencing is enabled on the tenant.
Applies To
  • Factor Sequencing
  • Adaptive MFA
  • FIDO2
  • Okta Classic Engine
Solution
With FIDO2 as the first factor in the sequence, locked-out users will still be able to log in. This has been determined by the Okta Product Team to be expected behavior, given the strength of FIDO2 as a factor. This behavior allows administrators to configure factor chains that allow legitimate users to sign in who may have had their accounts locked by malicious actors.
Loading
Why Can Locked Out Users Log In when Factor Sequencing is Enabled