<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007SKwzuCADOkta Classic EngineAuthenticationAnswered2022-04-13T13:05:34.000Z2022-02-23T12:26:08.000Z2022-04-13T13:05:34.000Z
  • Hello 

     

    Thanks for posting.

     

    1. Refer to Identity Providers for more information on how to create a SAML Identity Provider for MFA. For this workflow, navigate to Identify Providers > Configure Inbound SAML > Workflow > Part 1 – Add a SAML Identity Provider.
    2. Create the IdP factor with IdP usage as Factor Only. Note that JIT settings are not supported, and IdPs that are set as SSO only can't be used for Custom IdP factor.
    3. Once configured, navigate to Security > Identity Providers from the Okta console to add the Identity Provider.

     

    https://help.okta.com/en/prod/Content/Topics/Security/MFA_Custom_Factor.htm

     

    You can open a support case with our team using the information in the link below: https://help.okta.com/en/prod/Content/Topics/Directory/get-support.htm

     

     

    Let us know if this helps you.

     

     

    Daniela Chavarria.

    Okta Inc.

    Expand Post
  • TomerA.20484 (Customer)

    So I just tested this, and I think this is wrong for our use case.

    If I understand correctly, this feature will make users who just signed in to be required to sign in again using the "Factor IDP", right?

     

    I want the exact opposite. if a user can sign in using either a password or (for instance) GitHub, to be only prompted for MFA if they used their password, but if they used GitHub, not to be prompted for MFA at all.

     

     

    Expand Post
This question is closed.
Loading
Disable MFA for Social Login