<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00001FJNj00AHOkta Classic EngineMulti-Factor AuthenticationAnswered2026-02-27T17:04:46.000Z2026-02-04T10:07:03.000Z2026-02-27T17:04:46.000Z
Admin MFA disabled forgot to set the policy to disable MFA check. Now, locked out of the account itself

Hi team,

 

We are locked out of our Okta org due to an MFA device issue.

 

Situation:

- There were two devices enrolled earlier

- One device (mine) is no longer available

- The only remaining enrolled device is an iPhone belonging to another user

- We do NOT have an active Super Admin session available

- Login attempts now result in a 403 / access blocked

 

Because MFA is required and the available device is not accessible to me, I cannot complete authentication or access the Admin Console.

 

Request:

What is the correct recovery process when:

- MFA is enforced

- The admin’s enrolled device is no longer available

- Only another user’s device remains

- No Super Admin can currently log in

 

Please advise on admin recovery / escalation steps. We can provide org or domain ownership verification if required.

 

Thanks.

 


  • paul.stiniguta (Okta, Inc.)

    Hello @User17701983935681775947 (Customer)​ Thank you for posting on our Community page!

     

    It depends on what type of service you have with Okta.

    If you have a Paid service with Okta, you can open a case and Support will be able to reset your MFA and further help you in recovering the account.

    If you have a Free Integrator/Trial/Developer account, unfortunately these type of services do not have access to Support and there no way for us to provide further assistance.

    You may, however, create a new free trial/Developer account. We encourage you to always have a brake gals account for these type of situations.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • paul.stiniguta (Okta, Inc.)

    Hello @User17701983935681775947 (Customer)​ Thank you for posting on our Community page!

     

    It depends on what type of service you have with Okta.

    If you have a Paid service with Okta, you can open a case and Support will be able to reset your MFA and further help you in recovering the account.

    If you have a Free Integrator/Trial/Developer account, unfortunately these type of services do not have access to Support and there no way for us to provide further assistance.

    You may, however, create a new free trial/Developer account. We encourage you to always have a brake gals account for these type of situations.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • RohitU.50441 (Trevonix)

    If you are on paid license, you will be able to recover the tenant contacting support. Free plan has no way of recovery.

     

    If you are able to sort out either with support or by creating new tenants. I would recommend creating a break glass account with hardware token/Authenticators with hash stored securely. So whenever admins get locked out break glass could be used to help admins to recover the accounts.

     

     

    Expand Post

Loading
Admin MFA disabled forgot to set the policy to disable MFA check. Now, locked out of the account itself