Configure the password authenticator (2024)

This authenticator lets you enforce the use of passwords when users sign in to Okta or an app. You can customize complexity requirements, apply password rules to groups or individuals, and set lockout conditions. End users can reset forgotten passwords without the aid of a help desk.

The password authenticator is active by default for Okta users. To use the password authenticator, you have to configure a password policy and rules.

This authenticator is a knowledge factor and fulfills the requirements for user presence. See Multifactor authentication.

Before you begin

  • Create groups if you want to use them in a password policy. See Manage groups.
  • Create network zones if you want to use them in a password policy. See Configure a network zone.

Add a password policy

  1. In the Admin Console, go to SecurityAuthenticators.

  2. On the Setup tab, click ActionsEdit for the Password item.
  3. Click Add New Password Policy.

Configuration options

  1. Set the conditions for your password policy:

    Field

    Value

    Policy nameEnter a descriptive name for this policy.
    Policy descriptionEnter a description of what this policy does, and to whom it applies.
    Add groupEnter the groups of users that this policy applies to.
    Applies toSelect the authentication provider.
    Minimum lengthRequire a minimum number of characters in passwords.

    The minimum length is four characters. The maximum length is 30 characters.

    Complexity requirementsRequire various character types and other attributes to make passwords more complex.

    You can use Active Directory password requirements if you have AD-sourced users.

    Common password checkPrevent users from choosing commonly used passwords like "Password" and "11111111". Okta checks the user's password choice against the list of 1 million commonly used passwords. Combined with case-sensitive matching, this list covers over 2.5 billion common passwords.
    Password ageConfigure how long users can use passwords, how often they can reuse them, and when they're prompted to change their password.

    The minimum age is 0 (zero) days, and the maximum age is 999 days.

    Lock outConfigure these options:
    • The number of times an incorrect password can be entered before the account is locked.
    • How long the account remains locked.
    • Send users a lockout failure email when their account is locked.

    See Block suspicious password attempts from unknown devices

    To prevent AD and Lightweight Directory Access Protocol (LDAP) lockouts, verify that the number of unsuccessful attempts is lower than the failed sign-in attempt limit configured in AD and LDAP.

  2. Click Create Policy.
  3. Select the policy in the policy list.
  4. Click Add Rule.
  5. Configure the following options:

    Field

    Value

    Rule name Enter a name for the rule.
    Exclude users Enter the names of the users that you want to exclude.
    IF User's IP is
    • Anywhere: Apply the rule to all users regardless of whether their IP address is listed in the Public Gateway IP list.
    • In zone: Apply the rule to users in all or specific network zones.
    • Not in zone: Apply the rule to exclude users in all zones or in specific zones.

    See Network zones for information on the Public Gateway IP list and other IP Zones features.

    THEN User can perform self-service
    • Password change (from account settings): Allow users to change their password with the perform self-service password reset option.
    • Password reset: Allow users to perform self-service password resets through the Forgot password? link on the Sign-In Widget.
    • Unlock account: Allow users to unlock their account by clicking the Unlock account? link on the Sign-In Widget. When you select this option, LDAP-sourced Okta user accounts are unlocked in Okta but remain locked in the on-premises LDAP instance. If you don't allow self-service unlock, see Reset a user password for other options.
    AND Users can initiate recovery with
    • Okta Verify (push notification only): Allow users to initiate recovery with Okta Verify push notifications. See Configure the Okta Verify authenticator.
    • Phone: Allow users to initiate recovery with either text messages or voice phone calls. See Configure the phone authenticator authenticator.
    • Email: Allow users to initiate recovery with an email message that contains a one-time password or a magic link. See Configure the email authenticator.
    • Google Authenticator: Allow users to initiate recovery with a one-time passcode from Google Authenticator. See Google Authenticator.
    AND Additional verification is
    • Not required: Don't require additional verification from users during recovery.
    • Any enrolled authenticator used for MFA/SSO: Allow users to use any enrolled authenticator for recovery.
    • Only Security Question: Only allow users to use a security question for recovery. See Configure the security question authenticator.

    Admins can determine whether an authentication challenge must be completed before the user enters their password. In an authentication policy rule, configure the AND User must authenticate with option. See Add an authentication policy rule.

  6. Click Create rule.

Add the password authenticator to the authenticator enrollment policy

  1. In the Admin Console, go to SecurityAuthenticators.

  2. Click the Enrollment tab.
  3. Add the authenticator to a new or an existing authenticator enrollment policy. See Create an authenticator enrollment policy.

Edit or delete password policies and rules

You can't edit or delete the password authenticator, but you can edit or delete the policies associated with it. Before you edit or remove policies from this authenticator, you may have to update existing authenticator enrollment, authentication, and global session policies that use this authenticator.

  1. In the Admin Console, go to SecurityAuthenticators.

  2. On the Setup tab, click ActionsEdit for the Password item.
  3. Select a policy from the list to see its Edit and Delete options.
  4. Select a rule in the policy to see its options. To edit, click the pencil icon. To delete, click X.

End-user experience

End users are always prompted for a password unless an authentication policy rule for passwordless authentication is enabled. In AD, locked-out Okta users can use self-service account unlock, but only an admin can unlock a locked LDAP-sourced account.

Related topics

Self-service account recovery

Multifactor authentication

Configure the password authenticator (2024)

FAQs

How do I create a password for Authenticator? ›

Set up Google Authenticator for your Google Account
  1. On your Android device, go to your 2-Step Verification settings for your Google Account. You may need to sign in.
  2. Tap Set up authenticator. On some devices, tap Get Started.
  3. Follow the on-screen steps.

How do I reconfigure my Authenticator app? ›

  1. Step 1: Proceed to MFA security info site.
  2. Step 2: Delete the existing Microsoft Authenticator method.
  3. Step 3: Configure the Microsoft Authenticator app.
  4. Step 4: Choose the correct default sign-in method.
  5. Step 5: Test the app.

What is the Authenticator password? ›

An authenticator app is a mobile application that provides an extra layer of security to your online accounts by generating time-based one-time passwords (TOTPs). These passwords are used for two-factor authentication (2FA) and help protect your accounts from unauthorized access.

How do I fix my Authenticator problem? ›

Go to Settings and make sure push notifications are enabled and you have network connectivity. You can also remove your account and attempt the sign in again. If you are still not able to add your account, please contact Support or reach out to your IT admin.

How do I add a password to my Authenticator? ›

Open Authenticator and tap Passwords. Tap then Settings. Scroll down to Import Passwords and choose how you want to import.

What do I do if I forgot my authenticator password? ›

How to reset Authenticator password?
  1. Introduce the wrong password.
  2. Press on Forgot password.
  3. Select Start over.
  4. Once you confirm that you want to start over, you will be able to create a new vault and start from scratch.

How do I log into my authenticator app without password? ›

Open the authenticator app and set up your account in the app by following the prompts. Sign in to your Microsoft account Additional security options. Under Passwordless account, select Turn on. Follow the prompts to verify your account.

Where can I find my authenticator code? ›

Where can I find my authentication code? You will need to use open the authenticator app (such as Google Authenticator, Authy, or Duo) that you used when setting up the 2-factor authentication. Open the authenticator app and look for the code associated with your Wellfound login.

What to do if you can t access your Authenticator? ›

Google Authenticator apps are tied to a particular device and cannot be recovered remotely. But it is possible to recover Google Authenticator access to your account by logging in through a new phone or using the recovery codes provided when you first logged in.

How can I recover my Authenticator? ›

If you still have access to your old Authenticator and aren't using cloud backup, you can easily restore all of your accounts onto a new device by scanning your QR code with that device. The only way to recover Authenticator if you've lost your phone and weren't using cloud backup is to back up your QR code in advance.

How do I find my Google Authenticator password? ›

If you use Authenticator for 2-step verification to log in to your Google account but don't have access to Authenticator on your old device, you'll need to restore your Google account to get back in. To do this, go to https://accounts.google.com/signin/recovery.

How do I get my 6 digit code from authenticator? ›

If you select “Scan a barcode,” your phone's camera will activate. Hold your phone close to the screen to allow the camera to capture the QR code. 4. When the QR code or manual code has processed, Google Authenticator will generate a six-digit verification code and display it.

References

Top Articles
Chatham Patch Police Blotter
The Evolution of Kristen Archives: From its Origins to Now -
Devon Lannigan Obituary
Martha's Vineyard Ferry Schedules 2024
Videos De Mexicanas Calientes
Retro Ride Teardrop
Toyota gebraucht kaufen in tacoma_ - AutoScout24
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Fototour verlassener Fliegerhorst Schönwald [Lost Place Brandenburg]
Paula Deen Italian Cream Cake
Tlc Africa Deaths 2021
Cvs Learnet Modules
What is the difference between a T-bill and a T note?
Tcgplayer Store
6813472639
SXSW Film & TV Alumni Releases – July & August 2024
Q Management Inc
Ukc Message Board
Lawson Uhs
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Why do rebates take so long to process?
Teen Vogue Video Series
Greyson Alexander Thorn
How to Watch Every NFL Football Game on a Streaming Service
Surplus property Definition: 397 Samples | Law Insider
Stihl Dealer Albuquerque
Airtable Concatenate
Elbert County Swap Shop
fft - Fast Fourier transform
City Of Durham Recycling Schedule
Gma' Deals & Steals Today
Is Poke Healthy? Benefits, Risks, and Tips
Bfri Forum
Wells Fargo Bank Florida Locations
What Happened To Father Anthony Mary Ewtn
Composite Function Calculator + Online Solver With Free Steps
Gyeon Jahee
M3Gan Showtimes Near Cinemark North Hills And Xd
Clark County Ky Busted Newspaper
R&J Travel And Tours Calendar
ATM Near Me | Find The Nearest ATM Location | ATM Locator NL
Ludvigsen Mortuary Fremont Nebraska
How To Get Soul Reaper Knife In Critical Legends
Dollar Tree's 1,000 store closure tells the perils of poor acquisitions
8 Ball Pool Unblocked Cool Math Games
How to Print Tables in R with Examples Using table()
Mcalister's Deli Warrington Reviews
The power of the NFL, its data, and the shift to CTV
Expendables 4 Showtimes Near Malco Tupelo Commons Cinema Grill
Unlock The Secrets Of "Skip The Game" Greensboro North Carolina
Lesson 5 Homework 4.5 Answer Key
Craigslist Charles Town West Virginia
Latest Posts
Article information

Author: Allyn Kozey

Last Updated:

Views: 5951

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.