
btc60 (btc60) asked a question.
We have enabled OKTA verify and Google Authenticator as our MFA, this policy has been assigned to all users. Some users are using OKTA verify whereas some are using Google Authenticator. We want to disable Google Authenticator as an enrollment factor. Does disabling Google Authenticator in factor enrollment will affect existing users who are using Google Authenticator or will they still be able to authenticate.
Thanks
Kishore

Hello @btc60 (btc60),
From the Admin Console, navigate to Security > Multifactor.
The factor must be disabled in all factor enrollment policies before the factor type can be deactivated from the Factor Type tab.
Regards,
Natalia
Okta Inc.
Hi Kishore,
Thanks for the question. There are certain scenarios to be considered while answering the question:
Scenario 1: Google authenticator disabled, MFA policy not enforced to the application.
Impact: Users will be able to seamlessly authenticate to the application, even after the enrolled factor- Google authenticator being disabled. There will not be any impact with the user login.
Scenario 2: Google authenticator disabled. MFA policy enforced to the application
Impact: Users who are enrolled to Google authenticator will be enforced to enroll to any of the other enrollment factors available (eg: Okta Verify, SMS Authentication, etc.) in order to access the application, as there is MFA policy configured for the application.
Scenario 3: Google authenticator re-enabled
Impact: Users will be able to authenticate to the application with the same old enrolled Google authenticator profile.