
FemiT.98788 (Exiger) asked a question.
Dear all,
We have several applications hosted on Okta and we also have MFA in place. Earlier today, a number of our users noticed they are able to log into Okta without being prompted for MFA code.
We already checked our MFA exceptions and all these users who are able to login are not in any groups that are in the MFA Exceptions list.
Any ideas? As this is a security risk

Hi @FemiT.98788 (Exiger) , Thank you for reaching out to the Okta Community!
I recommend reviewing the Okta System Logs for the authentication events to see what policies are being hit by the users that "bypass MFA". To make things a bit easier, you could filter the logs by using a query like eventType eq "policy.evaluate_sign_on" .
Once you've identified the policy being hit, you can review its configuration to see if the users meet the criteria(s) for being prompted.
As you haven't mentioned the type of app affected by this, I wanted to mention that MFA cannot be enforced for SWA apps.
If you have a paid account with us, you can open a case or call the support line (Customer Support Account ID number required) to work with my colleagues from the Support Team to review the polices.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.