Manage the Okta Account Recovery Email Validity Period
Last Updated:
Overview
Okta allows administrators to manage the validity period for account recovery emails used for password resets and account unlocks. This configuration determines how long the recovery token remains valid before expiring.
Applies To
- Okta Classic Engine
- Password Reset
- Account unlock emails
- Reset/unlock recovery emails' validity
Solution
How is the validity period for the account recovery email managed?
Modify the account recovery email validity period by navigating to the authentication settings and adjusting the password policy configuration.
- Navigate to Security > Authentication.
- Select the Password Policy that requires modification and click Edit.
- Locate the Account Recovery section in the Policy window.
- Use the dropdown menu to modify the reset/unlock recovery email validity lifespan.
NOTE: Administrators can also manage the validity of the recovery token via the API, as detailed in the Authentication UI - Recovery Token documentation.
NOTE: Okta Identity Engine (OIE) limits the maximum lifetime of the email challenge to 30 minutes for security reasons. Review What Is the Maximum Lifetime of the Email Challenge For Email Authenticator for more information.
