<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta YubiKey Re-Authentication Behavior With Multiple Application Policies

Administration
Okta Identity Engine

Overview

YubiKey re-authentication behavior in an Okta environment depends on the authentication policies assigned to the accessed applications. A user receives re-authentication prompts more frequently than an administrator, even when accessing similar applications, due to differing authentication policies with varying re-authentication timers.

Applies To

  • Okta Identity Engine (OIE)
  • YubiKey
  • Authentication Policies

Cause

Users and administrators often fall under different authentication policies with varying re-authentication timers. Continuous use of various applications by an administrator triggers successful YubiKey authentications that repeatedly reset the primary Okta session timer, which delays the need for a re-authentication prompt.

Solution

How do shared authentication policies affect YubiKey re-authentication?

When multiple applications share the same authentication policy, a successful YubiKey authentication for one application resets the re-authentication timer for all other applications under that same policy.

 

Do applications with different authentication policies manage re-authentication requirements independently?

When applications have different authentication policies, Okta manages the re-authentication requirements independently. Authenticating into one application does not reset the re-authentication timer for another application. Okta prompts the user to re-authenticate for an application once the specific policy timeout reaches the limit.

 

Related References

Loading
Okta Support - Okta YubiKey Re-Authentication Behavior With Multiple Application Policies