<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Prompts for Password Before MFA When Require Possession Factor Before Password is Enabled

Administration
Okta Identity Engine

Overview

Okta prompts for a password before a possession factor when multi-factor authentication is not required, user enumeration prevention changes the prompt flow, or Classic Engine authentication endpoints handle the request. To restore the expected prompt order, confirm that multi-factor authentication is required and that Okta Identity Engine flows handle the sign-in request.

 

The user expects Okta to request a possession factor before a password after the Require possession factor before password setting is enabled. In some sign-in scenarios, Okta still displays the password prompt first on the initial authentication attempt.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • General Security
  • Protect against password-based attacks
  • Require possession factor before password during multi-factor authentication

Cause

Okta does not apply the Require possession factor before password setting when multi-factor authentication is not required, when user enumeration prevention changes the initial prompt, or when Classic Engine authentication endpoints process authentication.

Solution

How is the password-first prompt behavior resolved?

The following conditions identify when Okta does not prompt for a possession factor first:

  • Confirm that multi-factor authentication is required for the sign-in flow.
  • Check whether user enumeration prevention causes Okta to prompt for the email address or password first.
  • Verify that Okta Identity Engine authentication flows handle the request instead of Classic Engine authentication endpoints.

Related References

Loading
Okta Support - Okta Prompts for Password Before MFA When Require Possession Factor Before Password is Enabled