The goal of this knowledge article is to clarify why on the fly apps and self-service apps are now asking for MFA when they did not previously.
- Okta Identity Engine
- On The Fly Apps
- Self-service Apps
- MFA
This is documented in Okta Identity Engine Release Notes for 2023.11.1 as a Bug Fix for:
OKTA-667580 - Users weren’t prompted to reauthenticate when they revealed their credentials for personal apps.
This is considered a fix because this is how Okta behaved in Okta Classic and was tracked as a known vulnerability in Okta Identity Engine.
This is an enhanced security measure that was requested by the Okta security team and is expected new behavior.
No action needs to be taken by customers.
