<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Invalid Factor Sequencing Chain Blocks Okta Identity Engine Upgrade
Administration
Okta Identity Engine
Overview

The following reconfiguration has been identified as part of the preparation needed to perform the upgrade to Okta Identity Engine (OIE).

 

NOTE: Additional Okta features may require reconfiguration or be disabled in order to complete the upgrade. The active factor sequence chain should not contain two methods of the same authenticator in the same chain. The OIE upgrade cannot be scheduled until this is resolved.

Applies To
  • Okta Identity Engine Upgrade
  • Factor Sequencing
  • FACTOR_SEQUENCING_NO_SAME_ENROLLMENT
Cause

The upgrade to Okta Identity Engine (OIE) is blocked because an active factor sequencing chain contains two methods from the same authenticator type. The upgrade cannot proceed if a chain includes any of the following combinations:

  • Okta Verify and Okta Verify Push
  • Phone (Voice) and Phone (SMS)
Solution

To resolve this issue, modify the factor sequencing rule to ensure no chain uses two methods from the same authenticator type.

  1. In the Admin Console, go to Security > Authenticators.

  2. Select the Factor Sequencing tab.

  3. Review each rule to identify any chain that contains a prohibited combination of methods.

  4. Edit the conflicting rule by removing one of the methods or replacing it with a method from a different authenticator type.

  5. Click Save.

NOTE: If the conflicting chain cannot be identified, open each rule and select Update Rule without making any changes. This action removes any legacy policy configurations that may be blocking the upgrade.

Related References

Loading
Invalid Factor Sequencing Chain Blocks Okta Identity Engine Upgrade