
SteveR.88599 (Customer) asked a question.
Currently I have an app, Cisco VPN, that is setup for MFA but I would like the ability to create a group and assign it to the VPN App that bypasses Okta MAF - ie let's the log in just using their username and password. (I am trying to create one account I can share with different contractors we use without requiring each contractor to create an okta mfa account)

Hi Steve,
That's a great question, it is indeed possible. If you create a new sign on policy for no MFA. Assign this to a dedicated group created for no MFA and assign said users.
Once this is done, set the sign on policy as the first one in the list above previous MFA policies.
To adjust sign on policies: Security > Authentication
Here is some documentation surrounding the above: https://help.okta.com/en/prod/Content/Topics/Security/Security_Policies.htm?cshid=ext_Security_Policies
If you need further assistance on this, please do contact our support staff: https://support.okta.com/help/s/
Thank you