Create an authenticator enrollment policy
Create an authenticator enrollment policy to manage how and when your end users enroll authenticators. You can create policies specific to authenticators, user groups, and situations.
Before you begin
- Configure the authenticators that you want your users to sign in with. At least one authenticator must be enabled for authentication (MFA/SSO). The authenticators you configure must fulfill the security requirements of your org's sign-on policies. See Multifactor authentication.
- Grace periods aren't honored when authenticators are required, as required authenticator enrollment can't be skipped. For authenticators that require enrollment during Self-Service Registration (SSR), ensure that your authenticator enrollment policy isn't configured with a grace period.
- To use grace periods in your policy, your Sign-In Widget must be version 7.28 or later.
- (Early Access) To use the Passkeys (FIDO2 WebAuthn) promotion prompt, your Sign-In Widget must be version 7.48.1 or later.
Create a policy
-
In the Admin Console, go to .
- On the Enrollment tab, click Add a Policy.
- Enter a Policy name and Policy description.
- In Assign to groups, enter one or more user groups to which this policy should apply.
- For each authenticator you configured, indicate whether enrollment is Optional,
Required, or Disabled.
- At least one of your authenticators must be Required.
- Disabled isn't available for authenticators if another policy requires them.
- Set a Grace period for required authenticators:
-
None: Require users to enroll the first time they sign in.
-
End date: Set a date when users can no longer postpone enrollment of the authenticator. Until this date, users are prompted for enrollment once daily.
-
Skip count (Early Access): Indicate how many times a user may skip enrollment of the authenticator before it's required. Users are prompted for enrollment once daily until they reach this number.
-
- (Early Access) For the Passkeys (FIDO2 WebAuthn) authenticator, configure the following
settings to periodically prompt users who haven't enrolled a passkey to do so, without blocking their
sign-in:
Setting Description Passkeys (FIDO2 WebAuthn) Enrollment Set to Optional. Prompt users for enrollment - Select this checkbox to show an additional setup prompt that encourages users to enroll in passkeys.
- Clear this checkbox to disable the promotion prompt.
After every sign-in Select this option to show the prompt with every sign-in. After a duration Select this option to show the prompt on a recurring time-based interval. Enter a number and select a unit of time (days, weeks, or months) to set how often the prompt reappears. For example, if you specify two weeks, Okta shows the prompt every two weeks since the user saw it last time. Stop showing after number of skips - Select this checkbox and enter the number of skips allowed to limit how many times a user can dismiss the prompt before Okta stops showing it. After a user reaches this limit, Okta no longer prompts them to enroll.
- Clear this checkbox to always show the prompt, until the user enrolls.
-
Click Create policy. The policy appears on the Enrollment tab and is set to Active.
Edit a policy
-
To deactivate a policy, click the Active dropdown menu and select Deactivate. An inactive policy isn't applied to any users.
-
To update a policy, click the Edit button for the policy. Make changes and click Update policy. Note: If you change the grace period from End date to Skip count, the counter resets. If you already used skip counts and you change the amount, the number of times a user has already skipped enrollment persists. For example, if you changed from three to two skips, and the user has already skipped once, they have one skip remaining.
-
To delete a policy, click the Delete button for the policy. Once you delete a policy, it can't be recovered. You can't delete the default policy.
-
To reprioritize a policy, drag and drop it in the list to the desired level.
User experience
If a user hasn't enrolled a required authenticator when they access Okta or an Okta-protected app, the Sign-In Widget prompts them to complete enrollment. Then, users are prompted to enroll the optional authenticators, with an option to continue without enrolling. Users never see the disabled authenticators when signing in, even if they'd enrolled that authenticator.
Grace periods and app sign-in policies
If you configured a grace period for a required authenticator, users who satisfy the target app's app sign-in policy may continue to the app without enrolling until the grace period ends. Users who don't satisfy the target app's app sign-in policy must enroll the required authenticators immediately.
If the app's app sign-in policy requires users to enroll an authenticator before they can sign in, its grace period is ignored.
Sign-In Widget
The presentation of required authenticators differs slightly in the second and third generation Sign-In Widget.
-
In the second generation, users see all required authenticators in a single list. The Continue option only appears for those still in the grace period.
-
In the third generation, users see a list of authenticators that are required now and a second list of those that are still in the grace period (with the Continue option). If all the authenticators are still in the grace period, users see a single list with options to Remind me later.
Passkeys (FIDO2 WebAuthn) promotion prompt
- If you change the prompt frequency type (for example, from After every sign-in to After a duration), Okta resets the tracking history for all users. Each user's interval restarts upon their next sign-in.
- If you enable Stop showing after a number of skips when it was previously unchecked (no limit), Okta clears the current skip tracking for all users. Users are prompted again until they reach the newly specified skip limit.
- If you modify the duration value (for example, changing After a duration from two to four weeks) or adjust an existing number of skips, Okta maintains existing user tracking history:
- If you change the duration: Okta continues to calculate time from each user's last skip using the new duration.
- If you change the number of skips: Okta applies the updated limit to existing skip counts without resetting them. For example, if you change the skip limit from five to three and a user has already skipped the prompt twice, they will have only one skip left before Okta stops prompting them.