Okta YubiKey Re-Authentication Behavior With Multiple Application Policies
Last Updated:
Overview
YubiKey re-authentication behavior in an Okta environment depends on the authentication policies assigned to the accessed applications. A user receives re-authentication prompts more frequently than an administrator, even when accessing similar applications, due to differing authentication policies with varying re-authentication timers.
Applies To
- Okta Identity Engine (OIE)
- YubiKey
- Authentication Policies
Cause
Users and administrators often fall under different authentication policies with varying re-authentication timers. Continuous use of various applications by an administrator triggers successful YubiKey authentications that repeatedly reset the primary Okta session timer, which delays the need for a re-authentication prompt.
Solution
How do shared authentication policies affect YubiKey re-authentication?
When multiple applications share the same authentication policy, a successful YubiKey authentication for one application resets the re-authentication timer for all other applications under that same policy.
Do applications with different authentication policies manage re-authentication requirements independently?
When applications have different authentication policies, Okta manages the re-authentication requirements independently. Authenticating into one application does not reset the re-authentication timer for another application. Okta prompts the user to re-authenticate for an application once the specific policy timeout reaches the limit.
