
dr214 (dr214) asked a question.
we have disabled to Email authenticator in global session policy default rule. but still asking to setup/verify the AD mastered users during first login. The same settings we kept in trial tenant, there it is not asking. please assist.

Hi, @dr214 (dr214)
Thank you for posting on our Community page!
Check out the settings for both Global Session Policy and Authentication policy.
https://support.okta.com/help/s/article/Is-the-Global-Session-Policy-triggers-first-before-Authentication-Policies?language=en_US
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-policies.ht
You can check if you enabled Delegated Authentication for AD-mastered users in the trial tenant. AD-mastered users don't have to activate their accounts via the activation email. They can simply log in to Okta and activate their accounts if their user status shows as Active in Okta and delegated authentication is enabled in the tenant.
Also check in Security - Authenticators - Setup if Email is set as Authentication and Recovery.
Because there are multiple unknowns, I would advise you to open a case with Support for more in-depth checking.
Thank you for reaching out to our Community and have a great day!
_____________________________________________________________________________
What you missed: new product releases and other announcements
_____________________________________________________________________________
Community members help others by clicking Like or Select as Best on responses. Try it today.
_____________________________________________________________________________