
RajaR.78546 (Customer) さんが質問をしました。
Hi All,
Can someone please clarify me the below question.
- I have configured Azure AD SAML IDP in Okta using JIT.
- I have an Azure AD Profile sourced user(Service account with no email box access, its a non human account) assigned to Super Admin Role or Any other role in okta.
- When I am SSO by Azure IDP in okta using(Service account), the admin console sign-on policy required for one of the Factor type "Biometric or Possession, Knowledge".
- In my case as a Service account user i don't want any factor to access okta using Azure AD SSO.
- Reason: To create a API token using Service acc.

Hi @RajaR.78546 (Customer) , Thank you for reaching out to the Okta Community!
MFA is mandatory and enforced for the Admin dashboard, so all admin accounts should have MFA enrolled.
More details here.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
The new Okta Help Center YouTube channel is your go-to resource for tips, troubleshooting, and best practice videos. Subscribe today.
Join the Online Discussion for Ask me Anything on March 25, 2025: Identity Threat Protection with Okta AI