Okta First-Party App (FPA) Switcher Feature Does Not Evaluate Authentication Policy
Last Updated:
Overview
The Okta First-Party App Switcher feature allows administrators to swap between the End-User Dashboard and the Admin Console without a multifactor authentication (MFA) prompt. This behavior occurs because Okta keeps the session active in the background until the idle session expires. Administrators experience an unexpected bypass of the authentication policy that requires MFA at every sign-in to the Admin Console.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- First-Party App Switcher
- Authentication
Solution
Why does the Okta First-Party App Switcher bypass the authentication policy?
This behavior is expected. When the Okta First-Party App Switcher feature is active, and an administrator authenticates in the Admin Console, Okta keeps the session active in the background. The session remains active until the idle session configured at the Admin Console level expires.
NOTE: App Switcher rolled out to GA with the 2025.09.0 (September 2025) monthly release. At launch, four FPAs were included: Enduser Dashboard, Admin, Workflows, and Aerial. To request disabling this feature, contact Okta customer support.
