<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008GfSArSANOkta Classic EngineMulti-Factor AuthenticationAnswered2024-04-17T12:54:51.000Z2018-08-16T17:48:04.000Z2018-08-20T17:48:40.000Z
  • stxho (stxho)

    You have two choices for doing this. One is at a global level (affecting all of the apps in the given org) or two, at the app level... so setting specific groups to get MFA for AppA while everybody else not in that group will not get prompted for MFA for AppA...

     

    Here's how to do it for the org:

    Go to Security, Authentication, then SIgnOn tab. Create new or edit existing Sign On policy. One policy can contain multiple rules. At the policy level, set the Group you want to prompt for MFA. Then add a rule to your policy and in there you can set the conditions for when the group will get prompted for the MFA.

     

    Here how per App...

    Go to the Apps settings page, then to the Sign On tab for the app. In this tab scroll all the way down and add a rule... dig around in there and I think the rest will be obvious.

     

    Good luck!

    John

    Expand Post
    Selected as Best
  • stxho (stxho)

    You have two choices for doing this. One is at a global level (affecting all of the apps in the given org) or two, at the app level... so setting specific groups to get MFA for AppA while everybody else not in that group will not get prompted for MFA for AppA...

     

    Here's how to do it for the org:

    Go to Security, Authentication, then SIgnOn tab. Create new or edit existing Sign On policy. One policy can contain multiple rules. At the policy level, set the Group you want to prompt for MFA. Then add a rule to your policy and in there you can set the conditions for when the group will get prompted for the MFA.

     

    Here how per App...

    Go to the Apps settings page, then to the Sign On tab for the app. In this tab scroll all the way down and add a rule... dig around in there and I think the rest will be obvious.

     

    Good luck!

    John

    Expand Post
    Selected as Best
  • stxho (stxho)

    Also, note that if you set a Org level sign on rule that applies to Everybody and it says prompt for MFA inside and outside the network zone... then you proceed to set an App sign on rule to prompt MFA only for a certain group and only when they are off network, then that group and everybody else will always get prompted for MFA for that app... My point is you'll need to not only understand the order of policies and the way they apply within the App level or Org level but also how they impact each other between the Org and App levels.

    Expand Post
This question is closed.
Loading
Is there any way in okta to enable MFA for a user group.