Email Authenticator Limitations
Last Updated:
Overview
This article describes the limitations of the Email Authenticator.
Applies To
- Multi-factor Authentication (MFA)
- Okta Identity Engine
- Okta Classic Engine
Solution
Limitations of the Email Authenticator are:
- Okta always sends the authentication email to the end user's primary email address.
- If the end-user can access the Okta End-User Dashboard and the Okta End User Settings page, set the primary email address in the user profile as a read-only attribute. Any changes to an end user's primary email address will automatically enroll them in a new email authenticator and send any emails to their new address without additional confirmation.
- The Email authenticator is automatically enrolled for both authentication and recovery flows when a user verifies their primary email address or if the primary email address is provided when creating the user account. This ensures that the user does not receive redundant email enrollment challenges if they already prove they own the email address, such as after self-service registration, or if they are not required to prove they own the email address, such as when the admin creates the user account.
