<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Modify Protected Actions Configuration for the Admin Console
Okta Classic Engine
Okta Identity Engine
Administration
Overview

This article describes how to modify the configuration for Protected Actions. Protected Actions add a layer of security by requiring admins to re-authenticate when performing critical tasks in the Admin Console.

Applies To
  • Admin Console
  • Protected Actions

Solution

NOTE:

  • This feature is not available to federated users in Classic Engine orgs. Upgrading to the Okta Identity Engine is highly recommended.
  • Admins must allow pop-ups for their org URLs in their browser to use this feature.

Set the Authentication Interval

The authentication interval determines how often authentication is required when admins perform protected actions.

  1. In the Admin Console, go to Applications > Applications.

  2. Search for and select the Okta Admin Console app.

  3. Select the Protected actions tab.

Okta admin console

  1. Click Edit.

  2. In the Authentication required every field, select the desired authentication interval.

  3. Click Save configuration.

Select Protected Actions

  1. In the Admin Console, go to Applications > Applications.

  2. Search for and select the Okta Admin Console app.

  3. Select the Protected actions tab.

Okta admin console

  1. Click Edit.

  2. In the Select protected actions section, select the actions to protect.

  3. Click Save configuration.

Configure Email Notifications

Okta can send an email notification whenever an admin performs a protected action.

  1. In the Admin Console, go to Settings > Account.

  2. Go to the Admin email notifications section and click Edit.

  3. Select Admin performs a protected action.

  4. Click Save.

Admin email notification

Related References

Loading
Modify Protected Actions Configuration for the Admin Console