<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Effect of Disabling an Authenticator in the Enrollment Policy

Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

This article describes the experience of an end-user during authentication after an authenticator is disabled from an Enrollment policy.

Enrollment policy 

Applies To

  • Multi-Factor Authentication (MFA)
  • Enrollment Policy
  • Authenticators

Solution

The end-user will not be able to use that authenticator for Multi-Factor Authentication.

  • Users who are enrolled in an authenticator will be forced to enroll using any of the other enrollment factors available (for example, Okta Verify, SMS Authentication, etc.) to access the application.
  • If the disabled factor were the only other available factor, then the user would not be allowed to authenticate, as they would not be able to satisfy the authentication policy, which requires the second factor (see System Log Message "Access has been denied... for more information).
Error Message
  • Even though the disabled factor can not be used for Multi-Factor Authentication due to the current Enrollment policy, the end-user's enrollment in that factor is unaffected.
 
Loading
Okta Support - Effect of Disabling an Authenticator in the Enrollment Policy