<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Recovery Steps in Case of Integrator Free Plan Org Admin Account Lockout Post-MFA Enforcement
API Access Management
Okta Classic Engine
Okta Identity Engine
Overview

This article outlines recovery steps for when an administrator’s account gets locked out of an Integrator Free Plan Org after Multi-factor Authentication (MFA) enforcement.

403 Error

Applies To
Solution

If administrators are locked out of the Admin Console, follow these steps:

  1. Enroll in an MFA factor.
    • If other authenticators are enabled in the org, go to My Settings on the Okta End User Dashboard and enroll in an MFA factor before accessing the Admin Console.
  2. Sign up for a new Integrator Free Plan org.
    • Create a new account using plus addressing/subaddressing using the work email (provided that the corporate email provider, such as Google and Microsoft, supports it).
    • After creating a new Developer org, follow best practice recommendations such as:
      • Create multiple (3-5) Super Admin users in the organization.
      • Ensure all admins are registered for MFA.
      • Use this Terraform guide to establish access to a Terraform configuration for the Okta org in the event of being locked out.
  3. Migrate applications in the Okta Integration Network (OIN).
    • Independent Software Vendors (ISVs) who have published applications in the OIN should migrate their applications from the old developer org to a newly created Integrator org. To receive assistance with the migration, send an email to developers@okta.com with the subject: ISV - App Migration.

For any other issues, please reach out to the Okta Developer Forum.

 

Related References

Loading
Recovery Steps in Case of Integrator Free Plan Org Admin Account Lockout Post-MFA Enforcement