<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006G88KnSAJOkta Classic EngineMulti-Factor AuthenticationAnswered2019-05-21T05:19:12.000Z2019-05-20T02:08:10.000Z2019-05-21T05:19:12.000Z

JoelG.37773 (Customer) asked a question.

Is there a way to constrain allowed Factors to a subset of the configured factors?

For example, if I have both RSA SecurId and and Okta Verify configured (and need both for different scenarios), but I want users of a specific app to only use RSA, how do I do this?

Ideally it would be nice to have the option to be able to nominate allowed factors in my Sign On policies.


  • GabrielL.85945 (Customer)

    This functionality doesn't exist with Okta right now. You have an MFA policy that says what factors a user can enroll in. And then separately you have the sign on policies that determine when a user is challenged for MFA, but not the specific factor types they must use for that MFA challenge. So whenever a user is challenged for MFA, they will get to choose which factor to respond with, as allowed by the MFA policy.

     

    So if you have a user enabled to use both Okta Verify and RSA SecurID, then the user can choose which one they use when they do get challenged for MFA. You cannot say the user must respond to the MFA challenge with Okta Verify for app1, but must respond with RSA SecurID with app2.

     

    Seems like a good feature request, though.

    Expand Post
    Selected as Best
  • GabrielL.85945 (Customer)

    This functionality doesn't exist with Okta right now. You have an MFA policy that says what factors a user can enroll in. And then separately you have the sign on policies that determine when a user is challenged for MFA, but not the specific factor types they must use for that MFA challenge. So whenever a user is challenged for MFA, they will get to choose which factor to respond with, as allowed by the MFA policy.

     

    So if you have a user enabled to use both Okta Verify and RSA SecurID, then the user can choose which one they use when they do get challenged for MFA. You cannot say the user must respond to the MFA challenge with Okta Verify for app1, but must respond with RSA SecurID with app2.

     

    Seems like a good feature request, though.

    Expand Post
    Selected as Best
  • JoelG.37773 (Customer)

    Hi Gabriel, thank you. That seems like the best option using currently available functionality.​

    I'll probably put a feature request in for the ability to explicitly select Factors so we get more flexibility.

  • Hi Joel,

     

    Thank you for posting on our community page.

    Unfortunately, this is not possible at this point, at this point, I would recommend that you submit a feature request.

    While I was unable to find the Feature Request already listed, here's where you can submit your idea: https://support.okta.com/help/oktaideas

    This page is closely monitored by Engineering and used to filter and consider ideas for future implementation.

     

    Valentin Ion,

     

    Okta Support Engineer.

    Expand Post
This question is closed.
Loading
Is there a way to constrain allowed Factors to a subset of the configured factors?