
User15901888693787478890 (Customer) asked a question.
I'm having Duo Network Gateway integrated with Okta, is it possible to bypass MFA just for this app when MFA is enabled by default at organization level? e.g. users login to other apps still need MFA prompted.

Hi Yunchao,
Yes you can add a rule to exclude the users from the MFA policy. Even if the MFA is enabled at organization Level. Just to to your MFA policy & Add a rule to exclude the users from MFA. It should work.
Hi Sandeep,
Thank you for your reply. If I exclude the users from the MFA policy, they'll exclude from MFA for other applications as well. I just wanna disable MFA for a specific app. Is there any way to achieve this? Thanks!
Hi Yunchao,
I am not sure I am correclty understanding what you want to do.
MFA authentication is available both 'Sign-on' policy and 'Appliciton Sign-on' policy.
'Sign-on' policy: This policy will be aplied when user login to Okta.
'Applciation Sign-on' policy: This policy will be applied when user login to applicaiton after sign-on the Okta.
I thought all your apps has been enabled the MFA authentication (=Applicaiton Sign-on policy) indivisually.
If so, why don't you simply disable MFA authentication in the particular app(s) which you do not want to use MFA authenticaiton.
I hope this can help you.
Was there ever an answer to this?
The customer's scenario is:
MFA is currently enforced for everyone on the sign-on policy.
User just wants to exclude 1 app from MFA but keep MFA on all other apps through the sign-on policy.
Also looking for an answer to this. I have the exact scenario above.
Also looking for an answer to this
We have a similar scenario where we want to exclude one application mosyle for mfa which needs autherization for login accounts and we dont want users to have multiple screens.
Guess okta has this request for more than an year but they are not yet out with any solution.
Bump. We would like this option as well, to globally force MFA for all users and apps, but specifically exclude it from a specific app for all users of that app.
Hello,
For classic, you can achieve this with an app sign-on policy and app sign-on rule. In the rule, you can specify that if all of the conditions are met, the user will or will not be prompted for an MFA authentication.
ref: Step#7c: https://help.okta.com/en/prod/Content/Topics/Security/policies/configure-app-signon-policies.htm
App Sign On Policies can be set as rules on the Sign On tab of any integrated Okta app, the conditions of the rule for Sign On are set and the priority of rules can be altered much like Okta Sign On Policies.
The Prompt for Factor option could be turned off for a particular application by setting a rule for users assigned to the app as the priority 1 rule with the Prompt for Factor option unticked