Okta Prompts for Password Before MFA When Require Possession Factor Before Password is Enabled
Last Updated:
Overview
Okta prompts for a password before a possession factor when multi-factor authentication is not required, user enumeration prevention changes the prompt flow, or Classic Engine authentication endpoints handle the request. To restore the expected prompt order, confirm that multi-factor authentication is required and that Okta Identity Engine flows handle the sign-in request.
The user expects Okta to request a possession factor before a password after the Require possession factor before password setting is enabled. In some sign-in scenarios, Okta still displays the password prompt first on the initial authentication attempt.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- General Security
- Protect against password-based attacks
- Require possession factor before password during multi-factor authentication
Cause
Okta does not apply the Require possession factor before password setting when multi-factor authentication is not required, when user enumeration prevention changes the initial prompt, or when Classic Engine authentication endpoints process authentication.
Solution
How is the password-first prompt behavior resolved?
The following conditions identify when Okta does not prompt for a possession factor first:
- Confirm that multi-factor authentication is required for the sign-in flow.
- Check whether user enumeration prevention causes Okta to prompt for the email address or password first.
- Verify that Okta Identity Engine authentication flows handle the request instead of Classic Engine authentication endpoints.
