<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5KZ000018bHkW0AUOkta Classic EngineAdministrationAnswered2025-07-31T19:50:31.000Z2025-07-17T07:25:59.000Z2025-07-31T19:50:31.000Z

NamanS.35224 (Customer) asked a question.

Paid tenant :Locked Out of Okta Tenant Due to Misconfigured Certificate-Based Authentication (CBA) Policy

We are currently locked out of our Okta tenant due to a misconfiguration in the Certificate-Based Authentication (CBA) policy.

 

 

Issue Summary:

We recently applied a Certificate-Based Authentication (CBA) policy, but it was incorrectly configured to apply to all users. As a result, no users (including Admins) are able to log in to the Okta Admin Console or End-User Dashboard. We do not have any alternate authenticator or break-glass accounts excluded from this policy.

 

We urgently request the following:

 

1. Temporarily disable the CBA authentication policy or rule that is enforcing the certificate requirement.

2. Enable access to at least one Super Admin account using password + existing MFA (Okta Verify or TOTP).

3. Provide any alternate recovery options that may help restore admin access.

 

This issue is blocking all administrative operations and user access, so we would greatly appreciate your prompt assistance

 

For raising case it is asking to login through Okta identity engine workforce but eanble to do as on login it prompting CBA


This question is closed.
Loading
Paid tenant :Locked Out of Okta Tenant Due to Misconfigured Certificate-Based Authentication (CBA) Policy