Okta Administrator Account Lockout Recovery for Integrator Free Plan Organizations After MFA Enforcement
Last Updated:
Overview
Administrators who are locked out of an Integrator Free Plan organization after Multi-factor Authentication (MFA) enforcement must either enroll in an MFA factor or create a new organization to regain access. This situation occurs when an administrator cannot access the Admin Console due to missing MFA enrollment.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Integrator Free Plan Organization
- Multi-factor Authentication (MFA)
- Lockout
Solution
How does an administrator recover an account after an MFA lockout?
Regain access to the Admin Console by enrolling in an available Multi-factor Authentication (MFA) factor, creating a new Integrator Free Plan organization, and migrating existing applications.
- Enroll in an MFA factor. If the organization has other authenticators enabled, navigate to My Settings on the Okta End-User Dashboard and enroll in an MFA factor before accessing the Admin Console.
- Sign up for a new Integrator Free Plan organization. Create a new account using plus addressing or subaddressing with the work email address (provided that the corporate email provider, such as Google or Microsoft, supports it). For example,
<username+admin1@example.org>. - Implement best practice recommendations after creating a new Developer organization. Create multiple (three to five) Super Administrator users in the organization, ensure all administrators register for MFA, and use a Terraform guide to establish access to a Terraform configuration for the Okta organization in the event of a lockout.
- Migrate applications in the Okta Integration Network (OIN). Independent Software Vendors (ISVs) who have published applications in the OIN must migrate the applications from the old developer organization to a newly created Integrator organization. To receive assistance with the migration, send an email to
<developers@okta.com>with the subject: ISV - App Migration. - Contact the Okta Developer Forum for any other issues.
