
oabar (oabar) asked a question.
Is Okta actually taking into account the Password History requirements for Okta mastered accounts? I've set our Password Policy to not allow for the previously used password, but it does not seem to be taking effect. Has anyone seen issues with this? I know the default is set to previous 4 passwords - not sure if Okta doesn't allow for a number smaller than the default.

Hello Bolton,
Yes, the Okta Password History is taken into account, and there are only a few elevated permission conditions where it can be ignored which are not in use for user password flows, you can review these behaviors using the Okta User API: https://developer.okta.com/docs/reference/api/users/
Is the same issue occurring with the default set to 4 in this case? I would recommend you open a support ticket so that we can continue discussion on this topic, and clarify any configuration issues that might be present, if that is acceptable.
Thank you,
Bogdan Andrisan
Okta Customer Support