
SimonM.28559 (Customer) asked a question.
Hi all,
have a situation where we have two apps configured, and the business owners require different multifactor policies for each.
App 1 - password and google authenticator
App 2 - password and email code.
I can configure App 1 because you can select the hardware bound option, but I can't work out a way to configure app 2 so they aren't given the option for the google authenticator.
Thanks in advance.
Simon

Hello @SimonM.28559 (Customer) Thank you for reaching out to our Community!
You can do this with App sign on Policy and Multifactor App Condition Policy. Please see our documentation on this matter below:
https://help.okta.com/en/prod/Content/Topics/Security/MFA_App_Condition.htm
https://help.okta.com/en/prod/Content/Topics/Security/policies/about-app-signon-policies.htm
However if you are on OIE engine this can be done through App level policy, only please see below our doc for OIE:
https://help.okta.com/oie/en-us/Content/Topics/identity-engine/guides/asop/asop-app-policies.htm#:~:text=The%20app%2Dlevel%20sign%2Don,Okta%20Verify%20or%20provides%20biometrics.
Hi Paul,
Thanks for your response.
I think I'm almost there.
However, when a new user is enrolled, it's only asking them to set up a user password, not the 2FA part.
Consequently, they get into the dashboard, but can't launch the app because that 2FA authentication type hasn't been captured.
I presume this is in enrolment policies, but I can't see where to set this up.
Apologies for all the questions.
Thanks,
Simon
Hi Paul,
And I am now there.
Set this up in global session policies which seems to have done the trick.
Thanks for your help.
Cheers,
Simon