<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009ZzZ7hCAFOkta Classic EngineMulti-Factor AuthenticationAnswered2025-10-24T00:42:21.000Z2023-08-20T22:28:00.000Z2023-09-21T15:42:35.000Z

eninv (eninv) asked a question.

MFA Enrolment Policy - Query in OKTA classical engine

Can some please explain me what does the below two policies say, while enrolling the rule in MFA

 

  • Enroll Multifactor: Use the dropdown menu to enforce the following two options:
  • The user must enroll in the multifactor option during their initial sign-in to Okta.
  • The user can enroll when first challenged for an MFA option.

Bit confusing and seems both the rule conveys the same meaning

Video illustration would be more convenient


  • Hi,

     

    For more context on a potential use case see NIST's Authenticator Assurance Levels see https://sec.okta.com/articles/2023/03/setting-right-levels-assurance-zero-trust

     

    The first time a user signs in - regardless of what application is being accessed and what MFA requirements that application has, the user will be prompted to enroll in MFA based on the Multifactor Policy their account matches.

     

    The first time a user is challenged for MFA - if the Okta Dashboard or application the user is accessing does not require MFA, then the user will not be forced to enroll.

    Expand Post
    Selected as Best
  • Hi,

     

    For more context on a potential use case see NIST's Authenticator Assurance Levels see https://sec.okta.com/articles/2023/03/setting-right-levels-assurance-zero-trust

     

    The first time a user signs in - regardless of what application is being accessed and what MFA requirements that application has, the user will be prompted to enroll in MFA based on the Multifactor Policy their account matches.

     

    The first time a user is challenged for MFA - if the Okta Dashboard or application the user is accessing does not require MFA, then the user will not be forced to enroll.

    Expand Post
    Selected as Best
This question is closed.
Loading
MFA Enrolment Policy - Query in OKTA classical engine