<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Manage the Okta Account Recovery Email Validity Period

Administration
Okta Classic Engine
Okta Identity Engine

Overview

Okta allows administrators to manage the validity period for account recovery emails used for password resets and account unlocks. This configuration determines how long the recovery token remains valid before expiring.

Applies To

  • Okta Classic Engine
  • Password Reset
  • Account unlock emails
  • Reset/unlock recovery emails' validity

Solution

How is the validity period for the account recovery email managed?

Modify the account recovery email validity period by navigating to the authentication settings and adjusting the password policy configuration.

  1. Navigate to Security > Authentication.
  2. Select the Password Policy that requires modification and click Edit.
    Edit button
  3. Locate the Account Recovery section in the Policy window.
  4. Use the dropdown menu to modify the reset/unlock recovery email validity lifespan.
    Account Recovery

NOTE: Administrators can also manage the validity of the recovery token via the API, as detailed in the Authentication UI - Recovery Token documentation.

NOTE: Okta Identity Engine (OIE) limits the maximum lifetime of the email challenge to 30 minutes for security reasons. Review What Is the Maximum Lifetime of the Email Challenge For Email Authenticator for more information.

Related References

Loading
Okta Support - Manage the Okta Account Recovery Email Validity Period