
AlexC.39056 (Customer) asked a question.
Self-Service Unlock Account not sending Email/SMS — no System Log entry (OIE)
I'm on an Okta Identity Engine (OIE) tenant trying to get the self-service Unlock Account flow working, but users never actually receive the verification email/SMS, even though the UI walks through the full flow without any visible error.
What I've configured so far:
1. Security > Authenticators > Password > policy rule: "Users can perform self-service" > Unlock account is enabled.
2. Security > Authenticators > Email > "Used for (legacy)": set to "Authentication and recovery".
3. My password policy rule's Access control is set to "Authentication policy", which routes recovery/unlock through the Okta Account Management Policy (not the legacy rule).
- User has enrolled MFA Email and SMS is ACTIVE.
Symptom:
End-to-end, the widget correctly shows "Unlock account?" > username entry > "Verify it's you with a security method" > user selects Email > "Get a verification email" > clicks "Send me an email" > widget transitions to "Enter Code" screen as if it succeeded. But no email ever arrives (checked spam too), and there's no error shown anywhere in the widget.
What I've already checked:
- Reports > System Log: no entry at all for this user around the test timestamp for this flow — not even a failure/error event, it's just absent.
Has anyone run into this and found the actual root cause?
*identity-engine *self-service *account-unlock

Hello @AlexC.39056 (Customer) Thank you for posting on our Community page!
You are asking why users on an Okta Identity Engine tenant can complete the self-service unlock account flow through the UI (including selecting Email as the verification method and clicking "Send me an email"), but no verification email is ever delivered, and no corresponding event appears in the System Log—suggesting the email send request may not even be reaching Okta's email delivery system.
The most likely root cause is a mismatch between your authentication policy routing and the email authenticator configuration, or a missing email delivery configuration at the tenant level.
Root Cause:
When you configured the password policy rule's Access control to route through the Okta Account Management Policy (rather than the legacy rule), the unlock flow now uses OIE's modern policy engine. However, if the Email authenticator is still marked as "(legacy)" in Security > Authenticators > Email, there may be a disconnect: the OIE unlock flow attempts to send a verification email, but the legacy Email authenticator configuration does not have an active, non-legacy email delivery channel bound to it, or the Account Management Policy does not have permission to invoke email delivery for that authenticator. Additionally, if your tenant's email delivery is not fully configured or is restricted by IP allowlist rules, the email send request may silently fail without logging an event.
Solution:
Follow these steps to diagnose and resolve the issue:
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.