<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Prompts for Factor Enrollment During Password-Only Application Sign-In

Administration
Okta Identity Engine

Overview

After a migration to Okta Identity Engine (OIE), Okta prompts users to enroll in an authenticator during application sign-in because the enrollment policy rule lacks the correct application settings. Administrators must update the authenticator enrollment policy rule to include both Okta and applications.  Specifically, when a user attempts to sign in to a Security Assertion Markup Language (SAML) application that requires only a password, Okta prompts the user to enroll in a factor, such as Duo or Okta Verify, even when the enrollment policy disables all factors except the password.

Applies To

  • Okta Identity Engine (OIE)
  • Authenticator Enrollment Policy
  • Security Assertion Markup Language (SAML)

Cause

Okta Identity Engine (OIE) handles authenticator enrollment policies differently from Okta Classic Engine. The enrollment policy rule requires explicit configuration to apply to both Okta and applications.

Solution

How is the authenticator enrollment policy rule configured for applications?

Update the authenticator enrollment policy rule in the Admin Console to apply to both Okta and applications.

  1. In the Okta Admin Console, navigate to Security > Authenticators.
  2. Select the Enrollment tab.
  3. Select the enrollment policy applicable to the user group.
  4. In the Rule section, select Edit for the rule applicable to the user.
  5. Ensure that the Okta and Applications settings are enabled in the User is accessing section.

  Edit rule 

      1. Save the changes and test the configuration.

       

      Related References

      Loading
      Okta Support - Okta Prompts for Factor Enrollment During Password-Only Application Sign-In