<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y000081nTo7SAEOkta Classic EngineAdministrationAnswered2023-03-07T12:17:53.000Z2020-03-11T14:59:28.000Z2020-03-12T06:48:52.000Z

HenriD.35010 (Customer) asked a question.

How can I enable Okta Verify for password reset requests

At the moment, Okta only supports SMS and e-mail for password reset. Since both are easily compromised, I'm looking for a stronger factor to make sure the password request came from the correct user. How can I enable something like Okta Verify for password reset?


  • GabrielL.85945 (Customer)

    There's no functionality for that in Okta Verify, as it's strictly for MFA.

    I'd recommend combining SMS/email with answering a recovery question, along with hardening the password policies to restrict password changes (based on network zone, for example).

     

    Also, use MFA. If a password is compromised, from a password reset or otherwise, they won't be able to login without also responding to an Okta Verify challenge.

    Expand Post
This question is closed.
Loading
How can I enable Okta Verify for password reset requests