<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Multi-Factor Authentication Enrollment Policies Govern What Factors Users Can Invoke Instead of the Authentication Policies

Multi-Factor Authentication
Okta Identity Engine

Overview

A user who successfully enrolls in a Multi-Factor Authentication (MFA) factor can no longer use it for authentication after an administrator moves the user out of the Factor Enrollment Policy that enabled it. This occurs because Factor Enrollment Policies govern both the initial enrollment and the ongoing availability of a factor. Restore a user's ability to use an enrolled factor by ensuring the user belongs to a group associated with a Factor Enrollment Policy that has the desired factor configured as Optional or Required.

Applies To

  • Okta Identity Engine (OIE)
  • Factor Enrollment Policies
  • Multi-Factor Authentication (MFA)
  • Adaptive MFA

Solution

How is a user's ability to use an enrolled factor restored?

Restore a user's ability to use an enrolled factor by assigning the user to a group with an active Factor Enrollment Policy and designing policies for long-term access.

  1. Ensure the user is a member of a group associated with a Factor Enrollment Policy that has the desired factor configured as Optional or Required.
  2. Design Factor Enrollment Policies with the understanding that they permanently govern which factors are available to users.
  3. Structure policies around long-term user access needs rather than as temporary gates for initial enrollment.
  4. Build Global Session and Authentication policies to work in tandem with the established Factor Enrollment Policies.
Loading
Okta Multi-Factor Authentication Enrollment Policies Govern What Factors Users Can Invoke Instead of the Authentication Policies | Okta Support