Okta Prompts for Factor Enrollment During Password-Only Application Sign-In
Last Updated:
Overview
After a migration to Okta Identity Engine (OIE), Okta prompts users to enroll in an authenticator during application sign-in because the enrollment policy rule lacks the correct application settings. Administrators must update the authenticator enrollment policy rule to include both Okta and applications. Specifically, when a user attempts to sign in to a Security Assertion Markup Language (SAML) application that requires only a password, Okta prompts the user to enroll in a factor, such as Duo or Okta Verify, even when the enrollment policy disables all factors except the password.
Applies To
- Okta Identity Engine (OIE)
- Authenticator Enrollment Policy
- Security Assertion Markup Language (SAML)
Cause
Okta Identity Engine (OIE) handles authenticator enrollment policies differently from Okta Classic Engine. The enrollment policy rule requires explicit configuration to apply to both Okta and applications.
Solution
How is the authenticator enrollment policy rule configured for applications?
Update the authenticator enrollment policy rule in the Admin Console to apply to both Okta and applications.
- In the Okta Admin Console, navigate to Security > Authenticators.
- Select the Enrollment tab.
- Select the enrollment policy applicable to the user group.
- In the Rule section, select Edit for the rule applicable to the user.
- Ensure that the Okta and Applications settings are enabled in the User is accessing section.
- Save the changes and test the configuration.
