<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7UkySAFOkta Classic EngineSingle Sign-OnAnswered2025-08-04T09:00:34.000Z2015-12-04T15:55:28.000Z2017-08-06T14:58:38.000Z
j5v7c, g3aea, and ThomasC.60395 like this.
  • j5v7c (j5v7c)

    Is there a suggestion for how to manage this? How can we give people access to accounts which require security questions?
  • g3aea (g3aea)

    Hi Lazaros, Rachel, 

     

    You may look into OPP (Okta On-Premises Provisioning) and it can interact with either LDAP/OKTA API calls/REST (check https://support.okta.com/help/articles/Knowledge_Article/46749316-On-Premises-Provisioning-Deployment-Guide (https://support.okta.com/help/articles/Knowledge_Article/46749316-On-Premises-Provisioning-Deployment-Guide)) and though you may not be focusing on the "provisioning" part, it maybe a way to connect a non-SAML app to OKTA, or use something like DuoSecurity to enable MFA.  The problem you are trying to solve is indeed MFA just your own homebaked form instead; so as long as your policy allows for "any" MFA, there are lots of options actually.  The real problem youre highlighting is that OKTA does not have a native ability to plug into the "GINA" or now called the Windows Credential Provider (historically called the MSGINA.dll, it controls the native Windows Logon function) and I beleive since WIn 7 can support 3rd party "Custom Credential Providers").  But OKTA does not have this capability, yet.

     

    How is this application enforced and prompted/displayed, currently? Via a "logon script" and prompts you from an IIS website?

    Expand Post
  • mjpqt (mjpqt)

    Richard thank you for the reply. However what I mean by "Security Questions" is not the one that Okta uses (MFA), but the fields that a user needs to fill in AFTER they provide the username and password to an application. I think Okta needs to provide a custom application that can deal with types of applications and that should allow as many fields as possible.
This question is closed.
Loading
Security questions