
ojidd (ojidd) asked a question.
Is it possible to use a user's secondary email address as a means of verification when logging on to our Okta environment. The scenario we are trying to address is if a user does not have his/her smartphone with them, and cannot access their primary email as a result, how would they then gain access.

You would either need a separate SSO policy scoped to a temp group that allows PW only - not secure, but it would work > remove when they have their mobile with them next.
Or better would be offering more than 1 authenticator - like FIDO2, where they could use an alternate authenticator to sign. Really useful if someone looses their phone, gets a new one > they can log in with FIDO2, then setup Okta Verify again themselves.
Thank you Steve. I've not used FIDO2 before so will look that up. Appreciate the response!