The following reconfiguration has been identified as part of the preparation needed to perform the upgrade to Okta Identity Engine (OIE).
NOTE: Additional Okta features may require reconfiguration or be disabled in order to complete the upgrade. The active factor sequence chain should not contain two methods of the same authenticator in the same chain. The OIE upgrade cannot be scheduled until this is resolved.
- Okta Identity Engine Upgrade
- Factor Sequencing
- FACTOR_SEQUENCING_NO_SAME_ENROLLMENT
The upgrade to Okta Identity Engine (OIE) is blocked because an active factor sequencing chain contains two methods from the same authenticator type. The upgrade cannot proceed if a chain includes any of the following combinations:
- Okta Verify and Okta Verify Push
- Phone (Voice) and Phone (SMS)
To resolve this issue, modify the factor sequencing rule to ensure no chain uses two methods from the same authenticator type.
-
In the Admin Console, go to Security > Authenticators.
-
Select the Factor Sequencing tab.
-
Review each rule to identify any chain that contains a prohibited combination of methods.
-
Edit the conflicting rule by removing one of the methods or replacing it with a method from a different authenticator type.
-
Click Save.
NOTE: If the conflicting chain cannot be identified, open each rule and select Update Rule without making any changes. This action removes any legacy policy configurations that may be blocking the upgrade.
