<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006dj79jSAAOkta Classic EngineAdministrationAnswered2024-03-25T06:52:14.000Z2019-09-11T15:06:52.000Z2019-10-01T18:43:28.000Z

oabar (oabar) asked a question.

Okta Password History

Is Okta actually taking into account the Password History requirements for Okta mastered accounts? I've set our Password Policy to not allow for the previously used password, but it does not seem to be taking effect. Has anyone seen issues with this? I know the default is set to previous 4 passwords - not sure if Okta doesn't allow for a number smaller than the default.


  • Hello Bolton,

     

    Yes, the Okta Password History is taken into account, and there are only a few elevated permission conditions where it can be ignored which are not in use for user password flows, you can review these behaviors using the Okta User API: https://developer.okta.com/docs/reference/api/users/

    Is the same issue occurring with the default set to 4 in this case? I would recommend you open a support ticket so that we can continue discussion on this topic, and clarify any configuration issues that might be present, if that is acceptable.

     

    Thank you,

    Bogdan Andrisan

    Okta Customer Support

    Expand Post
    Selected as Best
  • Hello Bolton,

     

    Yes, the Okta Password History is taken into account, and there are only a few elevated permission conditions where it can be ignored which are not in use for user password flows, you can review these behaviors using the Okta User API: https://developer.okta.com/docs/reference/api/users/

    Is the same issue occurring with the default set to 4 in this case? I would recommend you open a support ticket so that we can continue discussion on this topic, and clarify any configuration issues that might be present, if that is acceptable.

     

    Thank you,

    Bogdan Andrisan

    Okta Customer Support

    Expand Post
    Selected as Best
  • BoltonB.40389 (Customer)

    Bogdan,

     

    Thank you for the feedback. I've looked at the "Update Profile" endpoint in the documentation you provided. Will the "strict" parameter stop the user from being able to use a password used years ago? We'd like for our users to be prohibited from using their previous password, but we want to allow for them to use it in the future...would that be allowed using the strict parameter?

    Expand Post
This question is closed.
Loading
Okta Password History