The global session policy is set to keep the session active for a certain amount of time, and the end user should not be prompted for any factor. However, the end user is prompted to re-authenticate each time the browser is closed.
- Okta Identity Engine (OIE)
- Multi-Factor Authentication (MFA)
Certain feature flag is not enabled. Thus, the session is not kept active.
If is desired to keep the user's session alive for a certain amount of time even if they close the browser, please open a ticket with Okta Support for future guidance on how to have this feature enabled, referencing this article.
Related References
- Why is a User Being Prompted for MFA
- Application Does Not Prompt for MFA when Configured To
- Why Are Users Not Prompted for App-Level MFA Immediately after Logging into Okta
- Change the Frequency of Okta MFA Prompts when Users Edit Their Security Factors in Account Settings
