<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Super Administrator Locked Out of Integrator Free Plan Tenant After Disabling MFA

API Access Management
Okta Identity Engine

Overview

A Super Administrator of an Okta Integrator Free Plan tenant can become locked out of their account after modifying the authentication policy. Specifically, this occurs if the administrator navigates to Security > Authenticators > Enrollment, edits the Default Policy, and sets all Multi-Factor Authentication (MFA) authenticators to disabled, leaving only the Password as Required. Subsequently, any attempt by the Super Administrator to log in fails, effectively locking them out of the tenant. Creating a new Integrator Free Plan organization resolves the issue.

Applies To

  • Okta Identity Engine (OIE)
  • Integrator Free Plan
  • Independent Software Vendor (ISV)

Cause

The lockout occurs because the administrator removes all required MFA methods for the Super Administrator account. The Integrator Free Plan mandates using MFA for administrator accounts as a security measure.

 

By intentionally disabling all authenticators except for the password, the administrator places the sign-on policy in a state that prevents successful authentication. Okta still expects a second factor that the edited policy no longer permits.

 

For free-tier accounts, such as the Integrator Free Plan, Okta Support does not provide manual account recovery or reset services for administrator lockouts.

Okta login

Solution

What steps resolve a lockout on an Integrator Free Plan tenant?

Create a new Integrator Free Plan tenant using an email alias, add a new Super Administrator to the new tenant, and continue with the Okta Integration Network (OIN) submission.

  1. Navigate to the Okta Developer sign-up page and create a new Integrator Free Plan tenant.
    NOTE: Okta recommends signing up using the same email address as the locked-out account, but with a "+" alias. Most email providers deliver emails sent to <same.email+alias@example.com> to the <same.email@example.com> inbox. For instance, if the original email was <admin@company.com>, administrators can sign up with <admin+oin@company.com>.
  2. Sign in to the new Integrator Free Plan tenant.
  3. Navigate to Security > Administrators to grant administrative access to other administrators or the original, unaliased email address.
  4. Select Add administrator.
  5. Follow the prompts to assign the Super Administrator role to the desired administrator.
  6. Proceed with the OIN submission using the new tenant and Super Administrator account.

 

Maintaining Multiple Authenticators Prevents Future Lockouts

Okta mandates MFA for administrators on the Okta Integrator Free Plan. To prevent a lockout, ensure that the enrollment policy always has at least two authenticators enabled.

Loading
Okta Support - Okta Super Administrator Locked Out of Integrator Free Plan Tenant After Disabling MFA