Email as an optional authenticator

Learn how email as an optional authenticator works after the upgrade.

Change summary The email authenticator is auto-enrolled for both authentication and recovery flows. This is a change from Classic Engine, where it's only available for authentication flows if the enrollment policy requires it.

Auto-enrollment ensures that the user doesn't receive redundant email enrollment challenges in the following scenarios:

  • They already proved they own the email address (users created through Self-Service Registration).
  • They don't need to prove they own the email address (admin-created users).

When email is set as an optional authenticator, primary emails are only auto-enrolled if you specifically enable the auto-enrollment setting within that policy. See Make email an optional authenticator.

Admin experience If you have a policy that requires email to be an Optional factor after the upgrade, you can manage email auto-enrollment and recovery behavior per policy. See Make email an optional authenticator. For the account recovery enrollment prompts that end users see when they don't have a required recovery authenticator, see Skip auto-enrolling email authenticator.

Otherwise, the email factor must be set to Disabled or Required before you upgrade. See the Classic Engine documentation: Configure an MFA enrollment policy.

Then, in Identity Engine, choose the setting for the email authenticator based on your use case:

  • Disabled: Recommended if the primary email accounts of your users are protected by Okta. Authentication emails are sent only to the primary email and not to the secondary email.
  • Required: Recommended for extended workforce use cases and Customer Identity and Access Management (CIAM) use cases. Validating the primary email is a common use case for these identities.

The default value for the email authenticator is five minutes, but you can increase the value in five-minute increments, up to 30 minutes. The accepted best practice is 10 minutes or less. If an end user clicks an expired magic link, they must sign in again.

User experience Email is auto-enrolled as an authenticator except when it's an optional authenticator. It may appear as an authenticator if other policies allow it, even when the user has enrolled in other required authenticators.

Depending on how the user is created and who sets the password, the user may not be prompted to enroll in other optional authenticators when they first sign in.

Related topics Make email an optional authenticator

Create an authentication enrollment policy

About authentication enrollment policies and rules