<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009rC3ZvCAKOkta Classic EngineAuthenticationAnswered2026-05-01T09:01:18.000Z2023-11-20T15:17:44.000Z2023-11-21T17:24:14.000Z

dse7i (dse7i) asked a question.

How to make password change require MFA?

I noticed that I was prompted to change my password, as it was expiring soon, but it asked me to change my password after entering my existing password but before I did got challenged for MFA. This seems wrong. Is there a way to require MFA first?


  • b5n6c (b5n6c)

    Hi Andrew,

    Thanks for reaching out to OKTA community.

    When you reset your password, you will be asked to enter existing password first and after that MFA will be prompted.

    After successfully MFA authentication it will allow you to create a new password .

  • Mihai N. (Okta, Inc.)

    Hi @dse7i (dse7i)​ , Thank you for reaching out to the Okta Community! 

     

    This is the expected behavior. Passwords are considered Authenticators under Okta Identity Engine and in a login flow which requires multiple Authenticators, each one is handled one at a time. 

    While I think I understand your concern, this flow does not pose a security threat in itself. 

    The worts case assumption here would be:

     

    1. that the threat actor first has access to the old password of an account (common case with let’s say phishing)
    2. an account which so happens to have the password expired at the time of the attack then to be able to get to the screen where they would get the “set up new password” screen (highly unlikely unless the expiration was triggered on purpose)
    3. then also somehow bypass the account’s MFA. (again highly unlikely) 

     

    I would also recommend always using additional stronger MFA options (not email, SMS, Voice Call) in all of your security policies. 

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    What you missed: new product releases and other announcements

    Expand Post
This question is closed.
Loading
How to make password change require MFA?