
p2dy6 (p2dy6) asked a question.
When configuring factor prompting within the app sign-on policy rules, does the "once per session" denote per app session or Okta session? If the Okta sign-on policy states a session lifetime lasts 2 hours, will apps re-prompt for MFA once the Okta session expires?

Hello @p2dy6 (p2dy6) If you check the Prompt for Factor checkbox, as shown below, three options appear that affect how end users are prompted for MFA in a given session.
wo of these options allow end-users to control these prompts while one disallows it.
Per Device: provides the option Do not challenge me on this device again on the end user MFA challenge dialog box. This option allows prompts solely for new devices.
Every Time: end users are prompted every time they sign in to Okta and cannot influence when they are prompted to provide a factor.
Per Session: provides the option Do not challenge me on this device for the next (minutes/hours/days) on the end user MFA challenge dialog box. You specify the Factor Lifetime in the accompanying Factor Lifetime field. When specifying per session, note that sessions have a default lifetime as configured, but sessions always end whenever users sign out of their Okta session.
The apps re-prompt for MFA once the Okta session expires, and not when the app session expires.
You can find additional information here:
https://help.okta.com/en/prod/Content/Topics/Security/policies/configure-signon-policies.htm#EndUserControlMFAPrompts
Regards,
Daniela
Okta Inc.