
TriH.41133 (Customer) asked a question.
We have a MFA rule that will invoke the MFA if the user is accessing Okta while off the network. Currently it is set to invoke MFA every time and the session expiration is defaulted to 2 hours.
Some users complain the MFA prompts are too aggressive and I am thinking about changing it to find a good balance for the end-user and IT security.
Here are my questions
- If I change the MFA policy to prompt for MFA "Per Device with the Session expires after 24 hours" will the user receive a MFA prompt the next day (after 24 hrs) on that same device?
- If I have the session to expire after 24 hours does that apply to Okta SP applications or does that session expiration apply only to the Okta web page?
I have opened a ticket with Okta support but they are still confirming. I hoping someone can shed some light or provide Okta documentation on the policy settings. Thank you.

I found this from the Okta Support page which seems to be working as designed!