<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Continuous MFA Prompt when Modifying Protected Actions in Classic Engine
Okta Classic Engine
Administration
Overview

When attempting to disable the Update protected actions settings option in the Okta Admin Console, the user is continuously prompted for Multi-Factor Authentication (MFA). This loop prevents the user from saving changes. This issue occurs in Okta Classic Engine environments when the administrator is signed in with a federated account.

Applies To
  • Okta Classic Engine
  • Protected Actions
  • Federated Administrators
Cause

In Okta Classic Engine, federated users cannot use the Protected Actions feature because they cannot perform the required step-up authentication. An Okta-sourced Super Administrator account is necessary to authenticate and authorize these changes.

Solution
  1. Sign out of the federated administrator account.

  2. Sign in to the Okta Admin Console using an Okta-sourced Super Administrator account.

  3. Choose Applications > Applications.

  4. Select the Protected Actions tab.

  5. Clear the Update protected actions settings checkbox.

NOTE: If an Okta-sourced Super Administrator account does not exist and cannot be created due to these restrictions, contact Okta Support.

For more information, refer to Protected actions.

NOTE: Once the organization upgrades to Okta Identity Engine (OIE), these settings can be re-enabled if needed.

Loading
Continuous MFA Prompt when Modifying Protected Actions in Classic Engine