
BrendanC.91294 (Customer) asked a question.
Custom role to configure MFA factors
Is there a capability to provide an admin access to configure MFA factors only via a custom role? We don't want to provide a user with Org Admin as this will provide more rights then necessary.

Sure! You can reference this link for the creation and management of Custom Administrator Roles
Please see below for examples:
Modifying these MFA factors at large for the org however, to me looks scoped to perhaps an Org Admin, although a closer look at your custom options may result in something specially crafted for what you need.
Hope that helps! Thanks!
Hi Don,
Thank you for the information however I've created a custom role and provided the user the above access but the ability to revoke/import yubikeys is still greyed out. Is there anything I am missing when setting up this role?
I believe the above is referring to the ability to reset a specific user's MFA settings, not necessarily modify MFA settings for an org. Like so:
I suspect, based on what I have read, that particular function may not be available to apply to a custom admin role. Thus, you may be left to rely on those roles that are pre-built.
I would definitely think that expanding this custom role capability is warranted, and I did recall that was discussed as a planned roll-out as discussed in Oktane 2022. Regardless, you can always submit this as a feature request here at Okta Ideas
Hopefully this helps to at least clear up any confusion. Thanks!!