
MichaelH.60933 (Customer) asked a question.
I'm trying to get all users to enroll both Okta Verfiy and a Security Question but only allow the Security Question factor to be used by a group of users ("People who forgot their phone today") and with certain network boundaries.
Is this achievable with AMFA?

All users can be enrolled for both factors like you're asking. Okta has no way to know that a user left their phone.
What happens is these users will be required to enroll for both factors upon next login ideally. When a user is prompted for MFA they have both factors enrolled but only one is there primary. Okta provides a drop-down to choose the factor. If the user forgets their phone they would use that drop-down and choose the secondary MFA factor they enrolled.
The other option is to only provide a secondary MFA option when those users call in to your Help Desk and add to the corresponding group that enforces that policy.
Hope that's helpful for you.