<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Effect of Disabling an Authenticator in the Enrollment Policy
Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine
Overview

This article describes the experience of an end-user during authentication after an authenticator is disabled from an Enrollment policy.

Enrollment policy 

Applies To
  • Multi-Factor Authentication (MFA)
  • Enrollment Policy
  • Authenticators
Solution

The end-user will not be able to use that authenticator for Multi-Factor Authentication.

  • Users who are enrolled in an authenticator will be forced to enroll using any of the other enrollment factors available (for example, Okta Verify, SMS Authentication, etc.) to access the application.
  • If the disabled factor were the only other available factor, then the user would not be allowed to authenticate, as they would not be able to satisfy the authentication policy, which requires the second factor (see System Log Message "Access has been denied... for more information).
Error Message
  • Even though the disabled factor can not be used for Multi-Factor Authentication due to the current Enrollment policy, the end-user's enrollment in that factor is unaffected.
 
Loading
Effect of Disabling an Authenticator in the Enrollment Policy