0D5WR000029R4xQ0ASOkta Classic EngineAuthenticationAnswered2026-09-21T15:21:28.000Z2026-09-18T09:25:07.000Z2026-09-21T15:21:28.000Z

AlexC.39056 (Customer) asked a question.

Self-Service Unlock Account not sending Email/SMS — no System Log entry (OIE)

I'm on an Okta Identity Engine (OIE) tenant trying to get the self-service Unlock Account flow working, but users never actually receive the verification email/SMS, even though the UI walks through the full flow without any visible error.

 

What I've configured so far:

 

1. Security > Authenticators > Password > policy rule: "Users can perform self-service" > Unlock account is enabled.

2. Security > Authenticators > Email > "Used for (legacy)": set to "Authentication and recovery".

3. My password policy rule's Access control is set to "Authentication policy", which routes recovery/unlock through the Okta Account Management Policy (not the legacy rule).

  1. User has enrolled MFA Email and SMS is ACTIVE.

 

Symptom:

 

End-to-end, the widget correctly shows "Unlock account?" > username entry > "Verify it's you with a security method" > user selects Email > "Get a verification email" > clicks "Send me an email" > widget transitions to "Enter Code" screen as if it succeeded. But no email ever arrives (checked spam too), and there's no error shown anywhere in the widget.

 

What I've already checked:

 

- Reports > System Log: no entry at all for this user around the test timestamp for this flow — not even a failure/error event, it's just absent.

 

Has anyone run into this and found the actual root cause?

*identity-engine *self-service *account-unlock


  • Paul S. (Okta, Inc.)

    Hello @AlexC.39056 (Customer)​ Thank you for posting on our Community page!

     

    You are asking why users on an Okta Identity Engine tenant can complete the self-service unlock account flow through the UI (including selecting Email as the verification method and clicking "Send me an email"), but no verification email is ever delivered, and no corresponding event appears in the System Log—suggesting the email send request may not even be reaching Okta's email delivery system.

    The most likely root cause is a mismatch between your authentication policy routing and the email authenticator configuration, or a missing email delivery configuration at the tenant level.

     

    Root Cause:

    When you configured the password policy rule's Access control to route through the Okta Account Management Policy (rather than the legacy rule), the unlock flow now uses OIE's modern policy engine. However, if the Email authenticator is still marked as "(legacy)" in Security > Authenticators > Email, there may be a disconnect: the OIE unlock flow attempts to send a verification email, but the legacy Email authenticator configuration does not have an active, non-legacy email delivery channel bound to it, or the Account Management Policy does not have permission to invoke email delivery for that authenticator. Additionally, if your tenant's email delivery is not fully configured or is restricted by IP allowlist rules, the email send request may silently fail without logging an event.

     

    Solution:

    Follow these steps to diagnose and resolve the issue:

    1. Verify the Email authenticator is not marked as legacy. Navigate to Security > Authenticators > Email. Check the "Used for" dropdown. If it says "(legacy)" or is set only to "Legacy only", change it to "Authentication and recovery" or "Authentication only" (depending on your use case). Save the change.
    2. Confirm the Okta Account Management Policy includes Email as a valid verification method. Navigate to Security > Authentication Policies. Find and open the Okta Account Management Policy. Review the policy rules to ensure Email is listed as an allowed authenticator for recovery/unlock flows. If Email is missing, add it or edit the rule to include it.
    3. Check your tenant's email delivery configuration. Navigate to Settings > Email. Verify that:
      • Email delivery is enabled for your tenant.
      • The "From" address is configured and valid.
      • If your tenant uses a custom SMTP relay or has IP allowlist restrictions, confirm that outbound email traffic is not being blocked.
    1. Search the System Log for email delivery events using the correct filter. Navigate to Reports > System Log. Use the search expression: eventType eq "system.email.delivery"
    2. and filter by the date/time of your test. If no events appear, the email send request is not reaching Okta's delivery system. If events do appear but show status "FAILURE", check the event details for the failure reason (e.g., invalid recipient, bounced address, rate limit).
    3. Test with a different user or email address. Create a test user with a known-good email address (preferably one you control directly, not a forwarded or shared mailbox). Attempt the unlock flow again and check both the System Log and your email inbox. This isolates whether the issue is tenant-wide or user-specific.
    4. If the System Log still shows no email delivery events, contact Okta Support. Provide the tenant name, test user ID, exact timestamp of the unlock attempt, and confirmation that you have verified steps 1–3 above. Okta Support can check backend logs to determine whether the email send request was rejected before it reached the delivery system.

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @AlexC.39056 (Customer)​ Thank you for posting on our Community page!

     

    You are asking why users on an Okta Identity Engine tenant can complete the self-service unlock account flow through the UI (including selecting Email as the verification method and clicking "Send me an email"), but no verification email is ever delivered, and no corresponding event appears in the System Log—suggesting the email send request may not even be reaching Okta's email delivery system.

    The most likely root cause is a mismatch between your authentication policy routing and the email authenticator configuration, or a missing email delivery configuration at the tenant level.

     

    Root Cause:

    When you configured the password policy rule's Access control to route through the Okta Account Management Policy (rather than the legacy rule), the unlock flow now uses OIE's modern policy engine. However, if the Email authenticator is still marked as "(legacy)" in Security > Authenticators > Email, there may be a disconnect: the OIE unlock flow attempts to send a verification email, but the legacy Email authenticator configuration does not have an active, non-legacy email delivery channel bound to it, or the Account Management Policy does not have permission to invoke email delivery for that authenticator. Additionally, if your tenant's email delivery is not fully configured or is restricted by IP allowlist rules, the email send request may silently fail without logging an event.

     

    Solution:

    Follow these steps to diagnose and resolve the issue:

    1. Verify the Email authenticator is not marked as legacy. Navigate to Security > Authenticators > Email. Check the "Used for" dropdown. If it says "(legacy)" or is set only to "Legacy only", change it to "Authentication and recovery" or "Authentication only" (depending on your use case). Save the change.
    2. Confirm the Okta Account Management Policy includes Email as a valid verification method. Navigate to Security > Authentication Policies. Find and open the Okta Account Management Policy. Review the policy rules to ensure Email is listed as an allowed authenticator for recovery/unlock flows. If Email is missing, add it or edit the rule to include it.
    3. Check your tenant's email delivery configuration. Navigate to Settings > Email. Verify that:
      • Email delivery is enabled for your tenant.
      • The "From" address is configured and valid.
      • If your tenant uses a custom SMTP relay or has IP allowlist restrictions, confirm that outbound email traffic is not being blocked.
    1. Search the System Log for email delivery events using the correct filter. Navigate to Reports > System Log. Use the search expression: eventType eq "system.email.delivery"
    2. and filter by the date/time of your test. If no events appear, the email send request is not reaching Okta's delivery system. If events do appear but show status "FAILURE", check the event details for the failure reason (e.g., invalid recipient, bounced address, rate limit).
    3. Test with a different user or email address. Create a test user with a known-good email address (preferably one you control directly, not a forwarded or shared mailbox). Attempt the unlock flow again and check both the System Log and your email inbox. This isolates whether the issue is tenant-wide or user-specific.
    4. If the System Log still shows no email delivery events, contact Okta Support. Provide the tenant name, test user ID, exact timestamp of the unlock attempt, and confirmation that you have verified steps 1–3 above. Okta Support can check backend logs to determine whether the email send request was rejected before it reached the delivery system.

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best

Recommended content

No recommended content found...