Email Auto-Enrollment Controls
Last Updated:
Okta Identity Engine (OIE) introduces two explicit per-policy controls that govern how email is handled for authenticator enrollment and password recovery. These controls are available to all orgs and replace the implicit global behavior that existed in Okta Classic. No pre-upgrade action is required — Classic-equivalent defaults are applied automatically, and the controls can be adjusted per policy at any time after the upgrade.
What changes with OIE: In Okta Classic, email enrollment and recovery behavior were managed globally with no per-policy granularity. In OIE, each Authenticator Enrollment Policy and Password Recovery Policy rule exposes two checkboxes that give admins precise control over which user populations auto-enroll email and which receive recovery messages at unverified addresses.
- Auto-enroll Email as an Authenticator — Controls whether the primary email address is automatically enrolled as an authenticator. Configured per Authenticator Enrollment Policy where the Email factor is set to Optional.
- Auto-enroll Email for Recovery — Controls whether recovery messages can be sent to unverified email addresses. Configured per Password Recovery Policy rule.
Applies To
- EMAIL_AUTO_ENROLLMENT_CONTROLS
- Okta Identity Engine (OIE)
- Authenticator Enrollment Policies
- Password Recovery Policies
How It Works
In Okta Classic, email enrollment and recovery behavior were governed globally. Email was enrolled as a factor automatically when available, and recovery messages could be sent to any associated email address regardless of verification status. Administrators had no per-policy control over these behaviors.
In OIE, email is a first-class authenticator. The two controls below replace the implicit Classic behavior and give admins the ability to target specific user populations:
- Auto-enroll Email as an Authenticator — When selected, the primary email address is automatically enrolled as an authenticator using the account profile when email is an available authentication method. When cleared, email is not auto-enrolled — users may enroll it manually or via an activation link.
- Auto-enroll Email for Recovery — When selected, recovery messages can be sent to unverified email addresses, matching Classic recovery behavior. When cleared, recovery messages are restricted to verified addresses only.
To preserve Classic-equivalent behavior at the point of upgrade, OIE applies the following defaults per policy automatically. No policy migration or pre-upgrade reconfiguration is required.
- Auto-enroll Email as an Authenticator — defaults to cleared, matching Classic behavior
- Auto-enroll Email for Recovery — defaults to selected, matching Classic behavior
NOTE: Secondary email is governed by a separate global control and is not affected by either setting.
Configuration
The two controls are configured independently per policy. Review and adjust each control for the relevant policies to confirm the behavior matches the intended experience for each user population.
Configure Auto-enroll Email as an Authenticator
This control appears on each Authenticator Enrollment Policy where the Email factor is set to Optional. Go to each applicable policy, review the setting, and select or clear it based on the intended behavior for the assigned population.
-
In the Admin Console, go to Security > Authenticators > Enrollment.
-
Select the policy name to open it.
-
Locate the Email factor row and select Edit.
-
Review the Auto-enroll Email as an Authenticator checkbox:
- Select to auto-enroll the primary email address as an authenticator at the next sign-in opportunity.
- Clear to require manual enrollment or enrollment via an activation link.
-
Save the policy and repeat for each Authenticator Enrollment Policy where Email is set to Optional.
Configure Auto-enroll Email for Recovery
This control appears within each Password Recovery Policy rule. Enable the Access Control section to expose the setting, then select or clear it based on the intended recovery behavior for that population.
-
In the Admin Console, go to Security > Authenticators > Setup.
-
Next to Password, select Actions > Edit.
-
Under Rules, select the edit icon for the applicable rule.
-
Scroll to the Access Control section and enable This Rule (legacy) and Email. This exposes the auto-enroll recovery option.
-
Review the Auto-enroll Email for Recovery checkbox:
- Select to allow recovery messages to be sent to unverified email addresses.
- Clear to restrict recovery messages to verified addresses only.
-
Save the rule and repeat for each Password Recovery Policy rule that governs an affected user population.
