
StevenP.08563 (Customer) asked a question.
Using the radius agent, & requests are making it from the 3rd party App to OKTA, however I get the above message in the error log.
Looking at the signon rules for this okta app , I see "Require multifactor every session".
This is not editable even by the superadmin.
Assuming this is the issue, how can I turn off MFA for this app? The app can send username/password but nothing else.

try by create another policy on top of default policy - apply it to users/groups - uncheck, prompt for factor .
this system is totally hosed.... I tried to delete that image and it crashes. Tried to add the right one and it crashes... anyway, I did create the additional rule and it doesn't work.
what is the third party app/tool.? cisco asa/check point vpn.? if so , avoid the radius policy use from app side..