
4eclq (4eclq) asked a question.
One of our users seems to be prompted for authentication / 2FA verification more often than necessary when using some apps.
I can see that the user has a valid session in the activity logs for the user, however, suddenly "Sign-on policy evaluation resulted in CHALLENGE" happens, and she's prompted to authenticate again.
I can see no reason why a session that is already valid and active just minutes before would prompt to verify again. In the raw CSV logs I also don't get any additional information. I also verified that her IP address doesn't change, which was my initial assumption.
Is there a way to find out why a challenge was requested?

Hello @4eclq (4eclq),
Are you having this issue with some specific applications?
Please check if you have some app sing-on policies that can be affecting the authentication process: https://help.okta.com/en/prod/Content/Topics/Security/policies/configure-app-signon-policies.htm
Regards,
Natalia
Okta Inc.