<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000A9lWupCQEOkta Classic EngineMulti-Factor AuthenticationAnswered2025-12-30T09:00:25.000Z2024-06-14T08:24:27.000Z2024-06-16T12:40:00.000Z

sjjmz (sjjmz) asked a question.

Can we have email as the only Authentication with security question for Recovery.

Hi,

 

Are we able to configure as such:

  1. Email to be the only authenticator which is used for authentication and recovery
  2. Security Question to be used for recovery only

 

When users enroll the first time, they are require to set up email and security question before they can sign in.

In the event if users forgot their password, they can perform self-service password recovery by answering the Security Question only.


  • User17157611498146715886 (Customer Support Online Community and Social Care)

    Hi @sjjmz (sjjmz)​ , thank you for contacting Okta Community!

     

    You can change this from the Okta Admin Dashboard side menu > Security > Authenticators. The Authenticators list should include Email. From Actions, select Edit. You can switch from “Recovery” to “Authentication and Recovery”. Next, you need to set up a new Password policy or a new rule under an existing Password policy. 

     

    Here are some articles that could help: 

    Authentication policies

    Manage self-service password reset

     

    Regards. 

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    • sjjmz (sjjmz)

      Hi Diana,

      I tried with enrolling a new user.
      The new user was enrolled without security question being enroll as mandatory.

      Hence, was wondering what step i would have miss.
      Expand Post
This question is closed.
Loading
Can we have email as the only Authentication with security question for Recovery.