<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Password Policy Fails to Apply to a Group

Administration
Okta Classic Engine
Okta Identity Engine

Overview

A password policy fails to apply to a group when the policy lacks active rules or when administrators delete the only assigned group, which deactivates the policy. Activating the associated password policy rule resolves this issue. Administrators observe that users assigned to a policy configured to never expire passwords still experience password expiration every 90 days.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Administration
  • Password Policy
  • Password Rules

Cause

Okta does not apply a password policy if the policy lacks active rules. Users must meet the conditions of at least one policy rule for Okta to apply the policy. Additionally, if administrators assign the policy to only one group and subsequently delete that group, Okta deactivates the policy.

Solution

How is an inactive password policy rule activated?

Review the password policy requirements to ensure users meet the conditions of at least one rule, and activate the inactive policy and rule associated with the group.

  1. Verify that users meet the conditions of at least one rule for the policy to apply.
  2. Assign a group to the password policy if the Assigned to groups field is blank.
    NOTE: If administrators deleted the group, the group policy becomes inactive, and the Assigned to groups field remains blank. Administrators must assign a group to the policy before they can activate it.
    Policy 
  3. Activate the password policy and the password policy rule if they are currently inactive.
    Rules



 

Loading
Okta Support - Okta Password Policy Fails to Apply to a Group