Configuring Multi-Factor Authentication for Applications in Okta Identity Engine
Last Updated:
Overview
Okta Identity Engine application sign-on policy settings control whether an application requires multi-factor authentication. Configure the application authentication policy rule to require two-factor authentication and set the required possession factor options.
The user needs an application to prompt for an additional authentication factor during sign-in.
Applies To
- Okta Identity Engine (OIE)
- Two-Factor Authentication (2FA)
- Multi-Factor Authentication (MFA)
- Application authentication policies
Solution
How is Multi-Factor Authentication configured for an application?
The following video walks through the process of securing an application with multi-factor authentication, using the Okta Admin Console application as an example.
These steps enable multi-factor authentication for an application by updating the application authentication policy rule in the Admin Console.
- Confirm that the organization has at least one authenticator enabled.
- Review the current authenticator configuration. If the organization does not have any authenticators enabled, Okta enables Okta Verify with a one-time passcode as the default authenticator. If authenticators already exist, Okta makes no changes.
- In the Okta Admin Console, go to Applications > Applications.
- Open the <App Name> App where 2MFA will be configured.
- Go to Sign On > User authentication, then select View policy details.
- Go to <App Name> app policy > Actions > Edit.
- Edit the rule by reviewing Add an authentication policy rule.
- Go to User must authenticate with, then select a two-factor option from the Dropdown menu.
- Review the following guidance before saving the rule:
- Every Sign-in Attempt is recommended, especially for the Okta Admin Console app.
-
- If multiple authenticators are set to optional, other than Okta Verify, more than one factor appears under Additional factor types.
- Select the required options for Possession factor constraints are.
- Select Save.
NOTE: For enforcing MFA to access the Okta Admin Console, review Enable MFA for the Admin Console for more information.
