Email as an optional authenticator
After you upgrade to Identity Engine, learn about the changes to email as an optional authenticator.
The Email authenticator is auto-enrolled for both authentication and recovery flows. This is a change from Classic Engine, where it's only available for authentication flows if the enrollment policy requires it.
Auto-enrollment occurs when a user verifies their primary email address or if you provide it when you create the user. This ensures that the user doesn't receive redundant email enrollment challenges if they already proved they own the email address (self-service registration) or if they don't need to prove they own the email address (admin-created users).
The Email factor must be set to Disabled or Required before you upgrade to Identity Engine. Then, in Identity Engine, choose the setting for the Email authenticator based on your use case:
|User experience||Email is auto-enrolled as an authenticator. It appears as an authenticator if allowed by the policy, even when the user has enrolled in other optional authenticators.
Depending on how the user is created and who sets the password, the user may not be prompted to enroll in other optional authenticators when they first sign in.
|Related topics||Create an authentication enrollment policy|