After the Okta Identity Engine (OIE) migration, the user is prompted to set (enroll) a Factor such as Duo or Okta Verify after attempting to Sign in to a SAML application even when the enrollment policy has all the Factors but Password disabled. This worked fine on the previous Classic version.
- After Okta Identity Engine (OIE) migration
- Okta Identity Engine (OIE)
- Having an application policy rule configured just to have the password
There is a difference in how this is configured between Classic and OIE, and this needs to be set on the Enrollment Policy rule.
- Go to the Admin Dashboard.
- Click on Security > Authenticators.
- Select the Enrollment tab > select the enrollment policy applicable to this user group.
- In the Rule section, click on the Edit rule applicable to this user.
- Ensure Okta and Applications settings are enabled in the User is accessing section.
- Save changes and test.
