<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Unenrolled Authenticators Displayed in Account Lockout Recovery Options
Multi-Factor Authentication
Okta Identity Engine
Overview

This article explains why end-users may see password recovery options that do not appear to be enabled in their assigned password policy. 

For example:

  1. Select only Email as a recovery option.

Recovery authentication

  1. Trigger the self-service password reset flow. 
  2. The user is offered the possibility to use other factors besides email.

Account recovery options

Applies To
  • Okta Identity Engine (OIE)
  • Account Recovery
  • "Users can initiate recovery with" Password Policy 
Cause

This issue occurs when the User enumeration prevention feature is enabled with the Recovery option selected. This security feature changes the account recovery experience to prevent attackers from discovering which authenticators a user has enrolled.

Recovery Option Enabled

 

 

Solution

To change this behavior, disable the Recovery option within the User enumeration prevention settings.

  1. In the Admin Console, go to Security > General.

  2. In the User enumeration prevention section, select Edit.

  3. Clear the Recovery checkbox.

Recovery option disabled

  1. Select Save.

After completing these steps, the account recovery page will only display authenticators that the user is enrolled in.

Recovery Authenticators

Self-service account recovery

Related References

Loading
Unenrolled Authenticators Displayed in Account Lockout Recovery Options