<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Application Does Not Prompt for MFA When Configured

Okta Identity Engine
Okta Classic Engine
Multi-Factor Authentication

Overview

An Okta application fails to prompt a user for Multi-Factor Authentication (MFA) when launched from the End-User Dashboard because the authentication policy never requires re-authentication for active sessions. Adjust the re-authentication frequency settings in the authentication policy to resolve this issue. This behavior presents when administrators configure the application authentication policy with User must authenticate with set to Password + Another Factor or Any 2 Factor Types, but the global session policy already satisfied the MFA requirement during the initial dashboard login.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Global Session Policy
  • Authentication Policy
  • Multi-Factor Authentication (MFA) Settings

Cause

This issue occurs when administrators select the Never re-authenticate if the session is active option in the authentication policy. When the global session policy requires MFA and the user logs into the End-User Dashboard, the Okta session satisfies the MFA requirement. Because the authentication policy never requires re-authentication, Okta does not prompt the user for another MFA challenge when accessing the application. The Password re-authentication frequency is and Re-authentication frequency for all other factors is options appear only when administrators select Password + Another Factor. These options allow administrators to specify different re-authentication intervals for the password and other factors. For example, an administrator might configure the policy to require users to re-authenticate with a password after eight hours and with a possession factor every time the user accesses the application.

Solution

How do administrators configure the authentication policy to require MFA for the application?

Modify the authentication policy for the specific application to require re-authentication at every sign-on or after a specified time period.

  1. Navigate to Admin Console > Security > Authentication Policies.
    Authentication Policies  
  2. Select the authentication policy assigned to the application.
  3. Choose Edit.
  4. Set Re-authentication frequency for all other factors is to Every Sign on, or select Re-authenticate after to configure a specific time interval.
    Re-authentication frequency for all other factors is  
  5. Select Save.

Related References

 

 
Loading
Okta Application Does Not Prompt for MFA When Configured | Okta Support