<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008MMRTlCAPOkta Classic EngineMulti-Factor AuthenticationAnswered2024-03-25T10:47:59.000Z2022-11-10T21:46:23.000Z2022-11-11T20:40:59.000Z
How to configure timeout for 'edit profile'/modifying 2FA settings

EDIT -- The behavior described here is exactly what I am referring to. Is there any way I can change that 15 minute setting, such that its effectively 0 (always ask for reauthentication)?

 

ORIGINAL POST:

When a user logs into their Okta portal, using FIDO 2FA, they can immediately go into their profile, and setup another 2FA (e.g. security key/biometric authenticator, or yubikey) without being prompted for authentication a second time. However, if they login and then after 30 minutes attempt to add another 2FA device, they have to click 'edit profile' and re authenticate before proceeding to add another 2FA device.

 

What is the setting that controls this behavior? I want to force users to reauthenticate before adding another 2FA device, regardless of how long they have been signed in.


This question is closed.
Loading
How to configure timeout for 'edit profile'/modifying 2FA settings