<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00009vwKsXSAUOkta Classic EngineSingle Sign-OnAnswered2020-11-20T05:50:28.000Z2020-11-16T02:31:26.000Z2020-11-20T05:50:18.000Z

DhaivatP.50964 (Customer) asked a question.

Mfa policy to challenge only enrolled users

Hello i have recently created an application in okta which uses okta's hosted sign in page to get the users signed in to the application. I have also implemented the factors api to enroll users for mfa. Thus when users initally login the mfa is disabled. Now, i want to set up an policy where the hosted sign in page challenges the user only if he has enrolled in an MFA.


DhaivatP.50964 likes this.
  • Hello Dhaivat,

     

    Have you tried setting the MFA as optional, and creating a rule to not automatically prompt for MFA enrollment?

     

    From the Admin Portal, go to Security, and and select Multifactor. From there, select the Factor Enrollment tab, and select your Multifactor Policy. If you do not have one, you'll need to create one, and assign it to a group. Set the factor as optional. At the bottom click on Add Rule, give the rule a name, and then in the bottom drop-down box, select Do Not Enroll.

     

    Let me know if this helps!

     

    Tim

    Okta, Inc.

    Expand Post
This question is closed.
Loading
Mfa policy to challenge only enrolled users