Okta Policy Error “This operation isn’t supported in the Okta account management policy”
Last Updated:
Overview
The following error occurs when attempting to add custom expressions that include device attributes (for example, device.profile.managed == True) to the Okta Account Management Policy:
This operation isn’t supported in the Okta account management policy
Applies To
- Policy
- Management and Monitoring
- Account Management
Cause
- Authenticator enrollment and unenrollment
- Password recovery
- Account unlock
This policy’s custom expression capabilities are limited to the context of these account management functions. Conditions based on device state or attributes, such as whether a device is managed, are not supported within the Account Management Policy. Device assurance is fundamentally a condition for accessing applications or resources, not for managing the account itself.
Solution
- Define access requirements based on device posture (for example, managed device, trusted device).
- Control user access to applications based on various conditions evaluated at the time of a sign-in attempt.
