
VallipuramK.91275 (Customer) asked a question.
How to enforce end users to have a backup method in case their authenticator is down?
How do I create a multifactor authorisation policy that requires people to set up a backup method in case the authenticator app stops working or is unavailable.

you can set the enroll policy with multiple authenticator like okta verify and WebAuthn.by yubikey or Windows Helle/Mac touch Id.
As I am fairly new to Okta, a stepwise method would be really helpful, as I do not want a make a mistake.
Many thanks
Hi @VallipuramK.91275 (Customer) , Thank you for reaching out to the Okta Community!
You will first have to set up authenticator enrollment policies to ensure the users have all set up multiple options, for example Google Authenticator and Okta Verify, or maybe a physical one would be better like a Yubikey (in case they lose the phone where the apps are), then you would have to configure your authentication policies to allow users to sign in with either one or the other.
Here are the guides on how to configure the policies (you’ll need to configure them according to your specific needs):
Authenticator enrollment policy: https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-mfa-enrollment-policies.htm
Authentication policies: https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-app-sign-on-policies.htm
I recommend testing in a preview/test environment to confirm the expected behaviors before applying the changes to production to avoid users being stuck.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Ask the Experts: Now Thru 1/31 Okta FastPass Engineering and Product Teams Answer Your Questions