<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Enrollment Limits for FIDO2, YubiKey, and Smart Card Authenticators

Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

Okta enforces specific enrollment limits for FIDO2, YubiKey, and Smart Card authenticators per user account. Accounts support up to ten FIDO2 authenticators, one YubiKey, and one Smart Card authenticator. Understanding these maximum limits ensures successful Multi-Factor
Authentication (MFA) configuration.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Authenticators
  • Multi-Factor Authentication (MFA)

Solution

What are the enrollment limits for Okta authenticators?

Review the following maximum enrollment limits for each authenticator type per user account.

  • Up to 10 FIDO2 (WebAuthn) authenticators per account.
  • One One-Time Password (OTP) YubiKey per account.
  • One smart card authenticator per account.
    • NOTE: Administrators can attach multiple smart card Identity Providers (IdPs) to the smart card authenticator.
Loading
Okta Enrollment Limits for FIDO2, YubiKey, and Smart Card Authenticators | Okta Support