Okta Password Policy Fails to Apply to a Group
Last Updated:
Overview
A password policy fails to apply to a group when the policy lacks active rules or when administrators delete the only assigned group, which deactivates the policy. Activating the associated password policy rule resolves this issue. Administrators observe that users assigned to a policy configured to never expire passwords still experience password expiration every 90 days.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Administration
- Password Policy
- Password Rules
Cause
Okta does not apply a password policy if the policy lacks active rules. Users must meet the conditions of at least one policy rule for Okta to apply the policy. Additionally, if administrators assign the policy to only one group and subsequently delete that group, Okta deactivates the policy.
Solution
How is an inactive password policy rule activated?
Review the password policy requirements to ensure users meet the conditions of at least one rule, and activate the inactive policy and rule associated with the group.
- Verify that users meet the conditions of at least one rule for the policy to apply.
- Assign a group to the password policy if the Assigned to groups field is blank.
NOTE: If administrators deleted the group, the group policy becomes inactive, and the Assigned to groups field remains blank. Administrators must assign a group to the policy before they can activate it. - Activate the password policy and the password policy rule if they are currently inactive.
