<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009RLgy0CADOkta Classic EngineSingle Sign-OnAnswered2025-10-11T09:01:02.000Z2023-07-07T04:13:56.000Z2023-07-10T16:12:01.000Z

lnllt (lnllt) asked a question.

If you have two different password policies for the same group, which one wins?

I went to Security -> Authentication -> Add new password policy.

I added a password policy for "group 1" and a different password policy also for "group 1".

Which of the two conflicting policies will be applied to the group?


  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @lnllt (lnllt)​ 

     

    Thank you for posting on our Community page!

     

    You can find out more about password policies here:

    https://help.okta.com/en-us/Content/Topics/Security/policies/about-password-policies.htm

     

    Basically, 

    “A password policy is evaluated using the following criteria:

    • Complex requirements are evaluated when the password is set.
    • On the current policy and when the user last set their password, unless the user's password is expired, in which case it remains expired.
    • For AD and LDAP-sourced users, the AD and LDAP complexity requirements should match the AD and LDAP instances.”

     

    Thank you for reaching out to our Community and have a great day!

    _____________________________________________________________________________

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    _____________________________________________________________________________

    Expand Post
  • lnllt (lnllt)

    Hi, that article doesn't describe what happens when multiple policies are applied to the same group.

    Through experimenting, I was able to work out that there is a ranking of policies (you can drag/drop using those highlighted dots).

    Image is not available
     

    This isn't made clear in the UI and is not mentioned anywhere in the article you linked.

    Expand Post
  • flz9z (flz9z)

    Yaa..that's correct policies updates based on the priority

This question is closed.
Loading
If you have two different password policies for the same group, which one wins?