Okta Enforces Factor Enrollment Despite an Active Grace Period
Last Updated:
Overview
Okta enforces factor enrollment despite an active grace period when users only have one factor enrolled and encounter a policy requiring at least two factors. To resolve this, users must enroll in more than one factor to skip enrollment during the grace period. This issue occurs when a user attempts to authenticate and Okta unexpectedly prompts them to enroll in a new factor without the option to skip, even though administrators configured a grace period.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Multi-Factor Authentication (MFA)
- Enrollment Policies
Cause
This behavior occurs when a user has only one factor enrolled, such as a password. When the user encounters an authentication policy that requires at least two factors, Okta prevents the user from skipping the enrollment to avoid an unsatisfiable state. An unsatisfiable state occurs when a user requires specific factors, lacks enrollment in those factors, and has no way to enroll in them.
Solution
Why does Okta prevent users from skipping factor enrollment during a grace period?
Users must have more than one factor enrolled to skip enrollment if the policy requires multiple factors. Ensure that users enroll in an additional factor to utilize the grace period functionality successfully.
