
User17072819158114200830 (Customer) asked a question.
Authentication policy to require one group to authenticate with Email OTP and another group with Okta Verify
Is it possible create an Authentication Policy that would require one group to authenticate with Email OTP and another group with Okta Verify. The closest option I see is the "Possession factor" authentication scenario in the "User must authenticate with" field but that selects both Email OTP and Okta Verify.

Hello @User17072819158114200830 (Customer) Thank you for reacting out to our Community!
The authentication policies as also tied to Factor enrolment policies. I would recommend to create separate enrolment policies for each group. Please also see our doc for this:
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-mfa-enrollment-policies.htm
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/create-auth-policy.htm
Community members help others by clicking Like or Select as Best on responses. Try it today.
Earn Today: New Okta Community Badges Have Arrived
Subscribe Today: The Okta Community is on YouTube
Hello @User17072819158114200830 (Customer) ,
Short answer : YES 😉
What you can do is :
When the user will trigger the authentication policy, he will fall inside the rule corresponding to his Okta groups.