When setting a factor in the Okta tenant to disabled and then attempting to delete it from Authenticators, an error will be prompted, indicating that it must first be removed from the available policies. The error specifies which policies require the factor to be removed.
Error shows:
Cannot remove Okta Verify at this time.
Cannot modify/disable this authenticator because it is enabled in one or more policies.
- Okta Factors API
- Multi-Factor Authentication (MFA)
- Delete Factors
If the Admin decides not to modify the policies and simply sets the factor again as Optional or Requested, the user will not be asked to re-enroll in the factor. The user will retain their factor as active, and from an End-user experience, there will be no change.
