<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5KZ000013Bs5E0ASOkta Classic EngineMulti-Factor AuthenticationAnswered2025-07-31T19:54:15.000Z2025-07-01T09:01:10.000Z2025-07-31T19:54:15.000Z

KentY.80489 (Customer) asked a question.

Okta Network IP Zone

The user request to whitelist their office IP address when access to Okta without 2FA.

 

I have added the user's office IP to the Network IP Zone to bypass the 2FA when they are in the IP zone range to access Okta.

After that, they still need to get 2FA to access Okta, even though they are in the IP zone.

 

is it because the policy required the group to use 2FA even in the IP zone? The user is inside the group.

/help/servlet/rtaImage?refid=0EMKZ000000xDD9


  • Hi @KentY.80489 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    Authentication policies and Authenticator Enrollment policies are two independent features with their own functions and applicability, as such it is possible for a user to be prompted for MFA (enrollment) event though the Authentication policy might be configured to not require the user to leverage MFA to log in.

    That being said, I recommend reviewing your Okta System Logs to confirm what policy is being hit when the user authenticates to confirm it is the intended one and that it is properly configured. In addition to that, please take into consideration that Authentication Policies are configured at app level, so you need to make sure that all applicable policies are configured for your intended exemption. 

      

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Expand Post
    Selected as Best
  • Hi @KentY.80489 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    Authentication policies and Authenticator Enrollment policies are two independent features with their own functions and applicability, as such it is possible for a user to be prompted for MFA (enrollment) event though the Authentication policy might be configured to not require the user to leverage MFA to log in.

    That being said, I recommend reviewing your Okta System Logs to confirm what policy is being hit when the user authenticates to confirm it is the intended one and that it is properly configured. In addition to that, please take into consideration that Authentication Policies are configured at app level, so you need to make sure that all applicable policies are configured for your intended exemption. 

      

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Expand Post
    Selected as Best
  • KentY.80489 (Customer)

    Hi Mihai Negoita,

     

    I saw the log and found it going to the Default policy. Then, I have created a new policy and moved it above the Default policy.

    Finally, it works! managed to bypass the MFA.

     

    Thank you so much for your help.

     

    Best Regards,

    Kent

    Expand Post
This question is closed.
Loading
Okta Network IP Zone