<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Configuring Multi-Factor Authentication for Applications in Okta Identity Engine

Multi-Factor Authentication
Okta Identity Engine

Overview

Okta Identity Engine application sign-on policy settings control whether an application requires multi-factor authentication. Configure the application authentication policy rule to require two-factor authentication and set the required possession factor options.

 

The user needs an application to prompt for an additional authentication factor during sign-in.

Applies To

  • Okta Identity Engine (OIE)
  • Two-Factor Authentication (2FA)
  • Multi-Factor Authentication (MFA)
  • Application authentication policies

Solution

How is Multi-Factor Authentication configured for an application?

 

The following video walks through the process of securing an application with multi-factor authentication, using the Okta Admin Console application as an example.

 

 

These steps enable multi-factor authentication for an application by updating the application authentication policy rule in the Admin Console.

  1. Confirm that the organization has at least one authenticator enabled.
  2. Review the current authenticator configuration. If the organization does not have any authenticators enabled, Okta enables Okta Verify with a one-time passcode as the default authenticator. If authenticators already exist, Okta makes no changes.
  3. In the Okta Admin Console, go to Applications > Applications.
  4. Open the <App Name> App where 2MFA will be configured.
  5. Go to Sign On > User authentication, then select View policy details.
  6. Go to <App Name> app policy > Actions > Edit.
  7. Edit the rule by reviewing Add an authentication policy rule.
  8. Go to User must authenticate with, then select a two-factor option from the Dropdown menu.
  9. Review the following guidance before saving the rule:
    • Every Sign-in Attempt is recommended, especially for the Okta Admin Console app.

Every Sign-in Attempt

    • If multiple authenticators are set to optional, other than Okta Verify, more than one factor appears under Additional factor types.

Additional factor types

  1. Select the required options for Possession factor constraints are.
  2. Select Save.

 

NOTE: For enforcing MFA to access the Okta Admin Console, review Enable MFA for the Admin Console for more information.

 

Related References

Loading
Okta Support - Configuring Multi-Factor Authentication for Applications in Okta Identity Engine