
User17333837903154001253 (Customer) asked a question.
Hi,
I'm trying to understand what is happening in our Okta classic.
we have 4 options for the users for MFA enrolment, all of them set to optional.
At first login user needs to set at least one.
Now, If I change the Sms authentication (for example) to be required, the user first login is as expected:
user first needs to set and validate the SMS. than it is being prompted with the option to enrol with additional factors if he like.
But if I set Email authentication to required - I get a different first experience.
the user will need to validate his email, and that is it. he will not be prompted to enrol in additional factors.
Do you know why is that? And if it is possible to change?

Hello @User17333837903154001253 (Customer) Thank you for posting on our Community page!
What you are seeing is expected behaviour. Email MFA is auto-enrolled and is ready to use as an MFA when the user logs in the first time.
https://help.okta.com/en-us/content/topics/security/mfa/email.htm
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Ask Us Anything about Okta FastPass - now thru December 11th.